DOE-STD-1104-2016, Review and Approval of Nuclear Facility Safety Basis and Safety Design Basis Documents (Invoked)
Functional areas: Safety Basis Design, Nuclear Facility Safety
This Standard describes a framework and the criteria to be used for approval of (1) safety basis documents, as required by 10 Code of Federal Regulation (CFR) Part 830, Nuclear Safety Management, and (2) safety design basis documents, as required by Department of Energy (DOE) Standard (STD)-1189-2016, Integration of Safety into the Design Process. This Standard provides requirements and guidance for preparation of Safety Evaluation Reports (SERs) and safety review letters for DOE nuclear facilities.
Version history and related documents
Supersedes
Earlier documents this one replaced.
Related documents
Document text
Text extracted from the attached file. Refer to the original document for the authoritative version.
Section 1
NOT MEASUREMENT
SENSITIVE
DOE-STD-1104-2016
December 2016
Superseding
DOE-STD-1104-2014
DOE STANDARD
REVIEW AND APPROVAL OF NUCLEAR FACILITY
SAFETY BASIS AND SAFETY DESIGN BASIS
DOCUMENTS
U.S. Department of Energy
Washington, D.C. 20585
DISTRIBUTION STATEMENT A. Approved for public release; distribution is unlimited.
DOE-STD-1104-2016
i
FOREWORD
1. This Standard describes a framework and the criteria to be used for approval of (1) safety
basis documents, as required by 10 Code of Federal Regulations (CFR) Part 830, Nuclear
Safety Management, and (2) safety design basis documents, as required by Department of
Energy (DOE) Standard (STD)-1189-2016, Integration of Safety into the Design Process.
This Standard provides requirements and guidance for preparation of Safety Evaluation
Reports (SERs) for DOE nuclear facilities.
2. This DOE Standard is approved for use and reference by DOE, including the National
Nuclear Security Administration (NNSA).
3. This Standard provides requirements and guidance for DOE review and approval of safety
basis documents consistent with 10 CFR Part 830 and its implementation guides and should
be used in conjunction with that rule and its implementing guidance for safety basis
documents. Title 10 of the CFR Part 830 establishes requirements for nuclear facility
Preliminary Documented Safety Analyses (PDSAs), Documented Safety Analyses (DSAs),
and Technical Safety Requirements (TSRs) or TSR-equivalent documents for environmental
restoration activities. DOE-STD-3009-94, Change Notice 1, January 2000, Preparation
Guide for U.S. Department of Energy Nonreactor Nuclear Facility Safety Analysis Reports,
“or successor document,” is the most prevalently used DOE safe harbor method. Other safe
harbor DSA methods include DOE-STD-3011-2016, Preparation of Documented Safety
Analysis for Interim Operations at DOE Nuclear Facilities; DOE-STD-1120-2016,
Preparation of Documented Safety Analysis for Decommissioning and Environmental
Restoration Activities; and DOE-STD-3016-2006, Hazard Analysis Reports for Nuclear
Explosive Operations.
4. DOE Order (O) 413.3B, Program and Project Management for the Acquisition of Capital
Assets, and DOE O 420.1C, Facility Safety, establish the requirements for safety design basis
documents and invoke the use of DOE-STD-1189-2016 for developing these documents.
This Standard provides requirements and guidance for DOE review and approval of safety
design basis documents consistent with DOE O 413.3B, DOE O 420.1C, and DOE-STD-
1189-2016 and should be used in conjunction with those documents, and their implementing
guidance for safety design basis documents.
5. This revision of the Standard provides improved clarity in the criteria and guidance for
review of safety basis documents. This revision is compatible with
DOE-STD-3009-2014, Preparation of Nonreactor Nuclear Facility Documented Safety
Analysis, as well as previous versions of Standard 3009 and other safe harbor documents.
This revision addresses new criteria and guidance related to prevention or mitigation of
accidents with mitigated offsite dose estimates below the Evaluation Guideline (EG) of 25
rem, and provides requirements for review and evaluation, and the minimum level of
approval authority.
http://www.directives.doe.gov/cgi-bin/explhcgi?qry1517806411;doe-131
http://www.directives.doe.gov/cgi-bin/explhcgi?qry1517806411;doe-131
DOE-STD-1104-2016
ii
Section 2
6. Throughout this Standard, the word “shall” denotes actions that are required to comply with
this Standard. The word “should” is used to indicate recommended practices. The use of
“may” with reference to application of a procedure or method, indicates that the use of the
procedure or method is optional.
7. Comments (e.g., recommendations, additions, and deletions) and any pertinent data that may
be of use in improving this document should be e-mailed to nuclearsafety@hq.doe.gov or
sent to:
Office of Nuclear Safety (AU-30)
U.S. Department of Energy
19901 Germantown Road
Germantown, MD 20874
mailto:nuclearsafety@hq.doe.gov
DOE-STD-1104-2016
iii
CONTENTS
FOREWORD ............................................................................................................................................................... I
1.0 INTRODUCTION ........................................................................................................................................... 1
2.0 APPLICABILITY AND SCOPE ................................................................................................................... 2
3.0 MANAGEMENT AND COORDINATION OF SAFETY BASES REVIEWS ......................................... 3
3.1 RESPONSIBILITIES AND AUTHORITIES .............................................................................................................. 3
3.2 DELEGATIONS OF AUTHORITY ......................................................................................................................... 4
3.3 PLANNING ........................................................................................................................................................ 5
3.4 INTERACTIONS ................................................................................................................................................. 7
3.5 ISSUE ORIGINATION AND RESOLUTION ............................................................................................................ 8
4.0 APPROVAL OF DOCUMENTED SAFETY ANALYSES ....................................................................... 11
4.1 BASES FOR APPROVAL ................................................................................................................................... 11
4.2 BASE INFORMATION ....................................................................................................................................... 12
4.3 HAZARD AND ACCIDENT ANALYSES .............................................................................................................. 13
4.4 DEFENSE-IN-DEPTH ....................................................................................................................................... 15
4.5 SAFETY STRUCTURES, SYSTEMS, AND COMPONENTS (SSCS) ........................................................................ 15
4.6 SPECIFIC ADMINISTRATIVE CONTROLS .......................................................................................................... 16
4.7 DERIVATION OF TECHNICAL SAFETY REQUIREMENTS ................................................................................... 17
4.8 SAFETY MANAGEMENT PROGRAMS ............................................................................................................... 17
4.9 EXISTING FACILITIES WITH MITIGATED OFFSITE CONSEQUENCE ESTIMATES OVER THE EG ......................... 18
4.10 CONDITIONS OF APPROVAL ............................................................................................................................ 19
4.11 REJECTION OF A DSA..................................................................................................................................... 21
Section 3
5.0 APPROVAL OF TECHNICAL SAFETY REQUIREMENTS ................................................................. 22
5.1 MANAGEMENT AND COORDINATION .............................................................................................................. 22
5.2 BASES OF APPROVAL ..................................................................................................................................... 22
5.3 TSR CONSISTENCY WITH THE DSA ............................................................................................................... 22
5.4 TSR CONSISTENCY WITH DOE G 423.1-1B ................................................................................................... 23
6.0 APPROVAL OF OTHER SAFETY BASIS RELATED DOCUMENTS ................................................ 25
6.1 UNREVIEWED SAFETY QUESTION PROCESS PROCEDURE ............................................................................... 25
6.2 DOCUMENTS THAT RESULT FROM POSITIVE USQ DETERMINATIONS............................................................. 25
6.2.1 Evaluation of the Safety of the Situation ................................................................................................ 25
6.2.2 Justification for Continued Operation ................................................................................................... 26
6.3 DOWNGRADES IN FACILITY HAZARD CATEGORIZATION TO “BELOW HAZARD CATEGORY 3” STATUS ......... 26
7.0 SAFETY EVALUATION REPORTS ......................................................................................................... 28
7.1 GENERAL DISCUSSION ................................................................................................................................... 28
7.1.1 Review of PDSAs .................................................................................................................................... 29
7.1.2 Review of Safety Basis Changes and DSA Annual Updates ................................................................... 29
7.2 SER CONTENT AND FORMAT ......................................................................................................................... 30
7.2.1 Title Page ............................................................................................................................................... 31
7.2.2 Signature Page ....................................................................................................................................... 31
7.2.3 Executive Summary ................................................................................................................................ 31
7.2.4 Review Process....................................................................................................................................... 31
7.2.5 Base Information .................................................................................................................................... 32
7.2.6 Hazard and Accident Analyses ............................................................................................................... 32
7.2.7 Safety Structures, Systems, and Components (SSCs) ............................................................................. 33
7.2.8 Specific Administrative Controls ............................................................................................................ 33
7.2.9 Derivation of Technical Safety Requirements ........................................................................................ 33
7.2.10 Safety Management Programs ............................................................................................................... 34
Section 4
DOE-STD-1104-2016
iv
7.2.11 Technical Safety Requirements .............................................................................................................. 34
7.2.12 Conditions of Approval .......................................................................................................................... 34
7.2.13 Records................................................................................................................................................... 35
7.3 SAFETY BASIS INFORMATION SYSTEM DATABASE......................................................................................... 35
8.0 SAFETY DESIGN BASIS DOCUMENTS ................................................................................................. 36
8.1 SAFETY BASIS REVIEW TEAM ........................................................................................................................ 37
8.2 REVIEW BASES FOR SAFETY DESIGN STRATEGY ............................................................................................ 38
8.3 REVIEW BASES FOR CONCEPTUAL SAFETY DESIGN REPORTS ........................................................................ 40
8.4 REVIEW OF LONG-LEAD PROCUREMENT SSCS ............................................................................................... 42
8.5 REVIEW BASES FOR PRELIMINARY SAFETY AND DESIGN RESULTS ................................................................ 42
8.6 APPROVAL BASES FOR PRELIMINARY DOCUMENTED SAFETY ANALYSES ..................................................... 44
8.7 SAFETY REVIEW LETTERS .............................................................................................................................. 47
8.7.1 Executive Summary ................................................................................................................................ 49
8.7.2 Review Process....................................................................................................................................... 49
8.7.3 Recommendation to Proceed .................................................................................................................. 50
8.7.4 Site and Facility Information ................................................................................................................. 50
8.7.5 Hazard Analysis ..................................................................................................................................... 50
8.7.6 Hazard Categorization ........................................................................................................................... 50
8.7.7 Safety Structures, Systems, and Components ......................................................................................... 51
8.7.8 Specific Administrative Controls ............................................................................................................ 51
8.7.9 Other Hazard Controls .......................................................................................................................... 51
8.7.10 Design Codes and Standards ................................................................................................................. 51
8.7.11 Safety Design Criteria ............................................................................................................................ 51
8.7.12 Conditions of Approval for Proceeding to the Next Stage of Design ..................................................... 51
8.7.13 Conclusion ............................................................................................................................................. 51
Section 5
9.0 REFERENCES AND ACRONYMS ............................................................................................................ 53
9.1 REFERENCES .................................................................................................................................................. 53
9.2 ACRONYMS .................................................................................................................................................... 54
DOE-STD-1104-2016
1
1.0 INTRODUCTION
This Standard describes a framework and the criteria to be used for approval of (1) safety basis
documents, as required by 10 Code of Federal Regulation (CFR) Part 830, Nuclear Safety
Management, and (2) safety design basis documents, as required by Department of Energy
(DOE) Standard (STD)-1189-2016, Integration of Safety into the Design Process. This Standard
provides requirements and guidance for preparation of Safety Evaluation Reports (SERs) and
safety review letters for DOE nuclear facilities.
10 CFR Part 830 establishes requirements for nuclear facility Preliminary Documented Safety
Analyses (PDSAs), Documented Safety Analyses (DSAs), and Technical Safety Requirements
(TSRs) or TSR-equivalent documents for environmental restoration activities. DOE Order (O)
413.3B, Program and Project Management for the Acquisition of Capital Assets, or successor
document, and DOE O 420.1C, Facility Safety, establish the requirements for safety design basis
documents and invoke the use of DOE-STD-1189 for these documents.
DOE review of the safety basis for nuclear facilities determines whether the safety basis has been
developed in a manner that provides reasonable assurance of adequate protection of workers, the
public, and the environment from adverse consequences, taking into account the work to be
performed and the associated hazards. The key safety basis documents are the DSA and the
TSR. In some situations, other safety basis documents include Justifications for Continued
Operations (JCOs) and Evaluations of the Safety of the Situation (ESSs). Changes (i.e.,
revisions, amendments, supplements, and addenda) to any of these safety basis documents also
constitute safety basis documents.
DOE review and approval of the safety design basis documents for nuclear facilities provides
reasonable assurance that the safety design basis is sufficient to proceed to the next phase of
design or construction. The key safety design basis documents addressed by this Standard are
the Safety Design Strategy (SDS), the Conceptual Safety Design Report (CSDR), the
Preliminary Safety and Design Results, and the Preliminary Documented Safety Analysis
(PDSA).
Safety and health assurance is improved by standardizing the DOE process and methods for
reviewing and approving the safety basis and safety design basis documents. Although complete
standardization of the process (e.g., standardized review plan) requires substantial commitments
and is complicated by the diversity and number of facility operations throughout the DOE
complex, certain benefits are gained by standardizing fundamental elements of the review and
approval process.
Throughout this Standard, the word “shall” denotes actions that are required to comply with this
Standard. The word "should" is used to indicate recommended practices. The use of "may" with
reference to application of a procedure or method, indicates that the use of the procedure or
method is optional.
Section 6
http://www.directives.doe.gov/cgi-bin/explhcgi?qry1517806411;doe-131
http://www.directives.doe.gov/cgi-bin/explhcgi?qry1517806411;doe-131
DOE-STD-1104-2016
2
2.0 APPLICABILITY AND SCOPE
This Standard is applicable to the review and approval of the safety basis and safety design basis
documents, including revisions such as required updates for DSAs and TSRs (i.e., 10 CFR Part
830 annual updates) for existing nuclear facilities. Therefore, this Standard is appropriate for
Hazard Category 1, 2, or 3 nuclear facilities (classified in accordance with DOE-STD-1027-92
Change Notice No. 1, Hazard Categorization and Accident Analysis Techniques for Compliance
with DOE O 5480.23, Nuclear Safety Analysis Reports) that document their safety basis in
accordance with 10 CFR Part 830. For new nuclear facilities and major modifications to existing
nuclear facilities, the review and approval processes for the SDS, CSDR, Preliminary Safety and
Design Results, and PDSA1 are focused on the safety adequacy of the proposed design to support
proceeding to the next phase of design or construction. The review and approval of the DSA and
TSRs are focused on operations and safety of the as-built facility.
This Standard focuses on management of the review and approval process, provides
requirements and guidelines for establishing the basis of approval, and recommends a format and
content for SERs and safety review letters. Specific review guidelines that are technical in
nature are more appropriately addressed individually by subject matter and require more detailed
guidance and discussion. Therefore, the text provides general guidelines as opposed to a
comprehensive list of technical safety criteria. This Standard does not constitute a Standard
Review Plan in the same context as used by the Nuclear Regulatory Commission.
This Standard is applicable to government-owned, government-operated facilities as well as
contractor-operated facilities owned by DOE.
This Standard cancels and supersedes DOE-STD-1104-2014.
1 For major modifications, in accordance with DOE-STD-1189-2016, the SDS will address whether there is a need
for a CSDR and/or Preliminary Safety and Design Results.
DOE-STD-1104-2016
3
3.0 MANAGEMENT AND COORDINATION OF SAFETY BASES
REVIEWS
3.1 RESPONSIBILITIES AND AUTHORITIES
Responsibilities and authorities relating to the review and approval of safety basis and safety
design basis documents are defined in requirement documents such as DOE rules and orders.
The paragraphs below provide a convenient summary, as well as clarifying guidance.
Appendix A to Subpart B of 10 CFR Part 830 states that “The DOE Management Official for a
DOE nuclear facility (i.e., the Assistant Secretary, the Assistant Administrator, or the Office
Director who is primarily responsible for the management of the facility) has primary
responsibility within DOE for ensuring that the safety basis for the facility is adequate and
complies with the safety basis requirements of Part 830.” It further states that “The DOE
Management Official is responsible for ensuring the timely and proper (1) review of all safety
basis documents submitted to DOE and (2) preparation of a safety evaluation report concerning
the safety basis for a facility.”
Section 7
DOE O 413.3B assigns the authority to the Program Secretarial Officer (PSO) to designate a
Safety Basis Approval Authority (SBAA) with the authority to review and approve safety basis
and safety design basis documents (see Section 8 for SBAA review and approval
responsibilities). By assigning responsibilities for the review and approval of the DSA and TSRs
to another individual, the DOE PSO for the facility establishes that individual as the designated
SBAA. Assigning responsibilities carries concurrent delegation of authority recognized by the
line management and those responsible for monitoring and auditing implementation of the Rule.
DOE-STD-1083-2009 (Reaffirmed 2015), Processing Exemptions to Nuclear Safety Rules and
Approval of Alternative Methods for Documented Safety Analyses, provides requirements for the
review and approval of DSA methods other than the “safe harbor” methodologies listed in Table
2 of Appendix A of 10 CFR Part 830.
The SBAA is responsible for providing a defensible review and approval of the DSA and TSRs,
documented in an SER. Achieving defensible review and approval is facilitated by an
independent review process. Since both the preparation of the DSA and TSRs and their review
and approval typically fall within the purview of the same SBAA, the SBAA should establish a
Safety Basis Review Team (SBRT) and assign an SBRT leader with the responsibility for
performing the independent review. In making this assignment, the SBAA ensures that the
review team leader has no responsibility for preparation of the DSA and TSRs under review and
possesses technical competence relevant to safety basis and facility operations. The details of
independently reviewing the DSA and TSRs, up to and including recommending approval to the
SBAA, are managed by the review team leader.
The SBAA is the single point of contact between DOE and the facility contractor for all matters
regarding review and approval of the DSA and TSRs. Directions and requests of the facility
contractor regarding the safety basis document review originate with the SBAA. Requests for
any material on the DSA or TSRs, determination of the significance of identified issues on such
material, and direction to the facility contractor for resolution of issues are approved by the
DOE-STD-1104-2016
4
single point of contact. Contractor interface responsibilities are typically delegated to the SBRT
leader, but the SBAA remains the final authority on any disputes. Transmittal of official
communications and directions involving significant work effort by the facility contractor are
coordinated with the Contracting Officer. Line management personnel and representatives of
organizations responsible for monitoring and auditing implementation of 10 CFR Part 830
coordinate their activities through the SBAA.
The SBAA has the specific responsibility of ensuring that the review and approval process
represents all DOE entities with interest in the facility under review and considers commitments
made to agencies outside of DOE. While the views of outside agencies may be considered,
outside agencies have no role to play in the formal approval process. Identifying safety issues
and their resolution may involve negotiations between concerned organizations. Issues raised by
any interested parties should be given proper consideration to enhance safety assurance. The
review team leader should be delegated the responsibility for managing the interface between the
safety basis preparers and other DOE entities and external agencies.
Section 8
On behalf of the SBAA, the review team leader coordinates the day-to-day aspects of managing
the review and approval process for the DSA and TSRs. General responsibilities in this capacity
include the following:
• Serving as the focal point for interface between DOE and the facility contractor for
review matters;
• Developing a DSA and TSR review plan, including review milestones developed in
consultation with the facility contractor;
• Establishing and managing the review team;
• Managing the overall review process, including planning and scheduling changes;
• Coordinating, scheduling, facilitating, and documenting issue resolution; and
• Preparing the SER.
The SBAA has the responsibility for ensuring adequate performance of the review team leader in
fulfilling assigned responsibilities.
3.2 DELEGATIONS OF AUTHORITY
Section 2 of Appendix A to DOE O 450.2, Integrated Safety Management, defines provisions for
delegation of authority for safety management functions. In accordance with DOE O 450.2, the
PSO may delegate SBAA responsibilities, but does not relinquish the ultimate responsibility for
approval of safety basis documents. In carrying out assigned responsibilities, the approval
authority, if not the PSO, is at all times accountable to the PSO. Approval of DSAs, TSRs, and
unreviewed safety question (USQ) procedures required pursuant to 10 CFR Part 830, subpart B,
Safety Basis Requirements, are required by DOE O 450.2 to not be further delegated below the
most senior-level program officer or deputy at a Field Element office unless concurrence is
obtained from the applicable Central Technical Authority (CTA).
DOE-STD-1104-2016
5
DOE O 450.2 also establishes minimum requirements for training and qualification for delegated
approval authorities. Specifically, minimum individual qualifications for the top-level program
officer in a Field Element office and the officer’s deputy include: (1) qualification as a Senior
Technical Safety Manager consistent with DOE O 426.1, Federal Technical Capability, and
(2) successful completion of the one week course Nuclear Executive Leadership Training.
Additional requirements may also be established by the PSO (e.g., National Nuclear Security
Administration (NNSA) Policy Letter BOP-10.002, Delegations of Nuclear Safety Authority and
NNSA’s Safety Delegation Procedure for the National Nuclear Security Administration dated
August 2009). This same level of qualification and training is also expected for top-level
program officers at Headquarters who review and approve DSAs and TSRs.
DOE O 450.2 also requires delegations to define any limitations to the authorities delegated. If
an approval is needed and the circumstances go beyond the expressed terms of a delegation, the
delegating authority assumes decisional authority. DOE O 450.2 also requires the duration of
delegations to be defined and periodic reviews of delegations (every two years) to be conducted.
For proposed changes to an existing facility safety basis where no viable control strategy exists
to prevent or mitigate the offsite dose consequence of one or more of the accident scenarios from
exceeding the Evaluation Guideline (EG), the cognizant PSO shall serve as the DOE approval
authority and this approval may not be delegated. In such cases, the approval authority shall
obtain concurrence from the CTA and consult with the Office of Environment, Health, Safety
and Security on the technical adequacy of the safety basis submittal.
Section 9
3.3 PLANNING
A review plan should be used to define the extent and details of the review process appropriate to
a specific safety basis document review and preparation of the associated SER or letter providing
the review conclusions. Similarly, a safety design basis document review plan should be used
for review of safety design basis documents and preparation of the associated SER or safety
review letter. The SBAA ensures that the size and expertise of the SBRT and review plan are
commensurate with the complexity and risk associated with the document being reviewed. For
simple updates and less complex reviews, a review plan may not be necessary. Well before
submittal of safety basis documents for approval, plans, and milestones should be developed in
coordination with the facility contractor where support by the contractor will be required (e.g.,
briefings on the DSA and TSRs, facility walkthroughs, and issue resolution). The review plan
should be tailored to the hazards and complexity of the facility/operations and should be
approved by the SBAA with a copy forwarded to the facility contractor for its information.
Basic components of a review plan should include the following:
• Scope, objectives, and basis of the review, including technical-, mission-, and/or project-
related influences impacting the extent and detail of the review;
• Methodology of the review, including basic task identification (e.g., major milestones of
“in-process reviews” as draft documents are being developed, formal reviews of
DOE-STD-1104-2016
6
contractor submittal of draft documents, and/or formal reviews of contractor-approved
final documents), objectives, and review criteria;2
• Resources required for the review;
• Review team preparation and process coordination (e.g., briefings, training on review
plan and review criteria, facility walkthroughs);
• Means of coordinating, monitoring, and documenting the review (e.g., periodic
monitoring of individual tasks, documentation of review efforts, formats for issue
submittal and responses, tracking of issues and their resolutions, and record keeping);
• Required SER reviews, concurrence and approvals; and
• Review schedule, including key milestones (e.g., dates of facility walkthroughs,
briefings, and/or meetings, calendar time allotted for issue submittal and issue resolution,
SER reviews, and final SER approval).
The SBRT develops the review plan from a general understanding of the overall facility mission,
hazard category, and existing safety basis and safety design basis documentation (e.g., approved
PDSA or DSA and TSRs). Typical considerations include facility hazard category, complexity
and diversity of operations, dominant accident concerns, apparent or known operational and/or
design vulnerabilities, hazard controls, safety impact of software failures, existing mission or
program influences (e.g., mission-related considerations and objectives), and time constraints for
the review and approval. Careful consideration should be given up-front to development of the
review plan, including milestones for subsequent updating of the plan due to major changes
safety basis document development schedule, provisions, or approach to its review (e.g. where
minor changes are made to the annual update of a DSA, a limited review focusing on the changes
may suffice). Many elements considered in planning the review will be summarized as part of
the SER to document the basis and the extent and detail of the review. Documentation
establishing the basis and conduct of the review is maintained for subsequent demonstration that
the review process was complete and adequate.
Section 10
An important part of planning is selecting the individuals who comprise the review team.
Members of the review team are typically selected based on technical qualifications, experience,
familiarity with the subject matter, independence from preparation of the document(s) being
reviewed, understanding of DOE’s nuclear safety requirements, and availability. The review
team requires a core team with expertise in assessing process hazards analysis and accident
analysis. The core of the review effort is assessing the hazard and accident analyses in the DSA
2 Review criteria described in the plan should be based on the approval bases described in this Standard (based on
the type of document(s) being reviewed), as well as requirements and expectations stated in 10 CFR Part 830,
DOE-STD-1189, DOE-STD-1186, and safe harbor methods identified in 10 CFR Part 830, Subpart B, Appendix
A, Table 2. DOE G 226.1-2A, Federal Line Management Oversight of Department of Energy Nuclear Facilities,
provides relevant discussion on the development and use of criteria review and approach documents.
DOE-STD-1104-2016
7
because they are the primary sources of original material with which the remainder of the DSA is
aligned.
In addition, the core review team should also have expertise in assessing hazard control
selection, safety function description, functional requirements definition, and performance
criteria; these functional areas are also essential to an effective safety basis. The size of the
review team should be commensurate with the complexity of the review; in some cases, the
review team may only need one member.
In cases where the SBRT has multiple review team members and the review is complex (such as
for a new facility or major modification), at least one member of the SBRT shall meet the
requirements of DOE-STD-1183-2007, Nuclear Safety Specialist Functional Area Qualification
Standard, or approved successor document. Other personnel with diverse experience in safety
and health, facility operations, safety systems, and safety software are not necessarily members
of the core team, but collectively provide support as needed for a thorough assessment of the
facility safety basis. The extent of support necessary is generally reflected by the hazard and
complexity level of the activities being examined. Personnel resources may be augmented with
available personnel from DOE Headquarters or unaffiliated Field/Operations Offices. When
appropriate, a comprehensive and integrated review team should be established with
representatives from organizations identified to perform reviews and/or oversight of the DSA
and TSRs approval.
3.4 INTERACTIONS
DOE has certain fundamental limits on its ability to completely separate the contractor
preparation of safety basis documents and DOE’s review processes because DOE is responsible
for both the operation and regulation of the facilities for which such documents are prepared,
reviewed, and approved. Therefore, DOE reviews are not expected to be conducted completely
segregated from contractor safety basis development activities. Some degree of interaction
between the contractor preparation team and the review team would be helpful in streamlining
the review and approval process. This interaction provides the means by which DOE keeps
abreast of issues that arise during safety basis development and by which DOE responds to
requests from the preparer to assist in resolving fundamental conceptual issues. It is through
such interaction that DOE is afforded the opportunity to commence efforts to better understand
potential issues in preparation for the official review.
Section 11
It is important to maintain a balance in the interaction of the review and preparation processes.
The SBRT should be careful to remain independent of the development of the safety basis
documents to ensure independence in the review of those documents. To the extent practicable,
the SBRT should not include team members responsible for management or oversight of the
design of the facility.
Requests for material outside the provisions of the review plan should be made solely by the
review team leader. Reviewers should not directly request draft material from the preparers.
Informal requests or direction by reviewers is unacceptable. Tendencies exist for facility
contractors to view any comments or direction offered by reviewers as a firm prerequisite for
approval. The actual preparation of, and changes to, safety basis documents are the
DOE-STD-1104-2016
8
responsibility of the preparers, not the review team or its members. The SBAA is the only
authority for directing any official interventions driving the content and details of safety basis
documents. Any intervention should be officially communicated by DOE to the facility
contractor after ensuring that it is essential to the development of the facility safety basis and
originates from a sound technical foundation (i.e., undergone technically qualified independent
review).
3.5 ISSUE ORIGINATION AND RESOLUTION
Historically, in reviewing contractor safety basis documents, both DOE line management
personnel and representatives of other organizations generated a large number of comments,
some of which are not commensurate with a consistent concept of the facility safety basis and its
purpose. The preparer of the safety basis documents was responsible for resolving all such
comments, while reviewers were not required to provide technical justifications for comments.
This often resulted in forced integration of contradictory comments or comments contrary to a
particular approach or structure for the safety basis document.
To prevent such occurrences, the SBAA, through the review team leader, maintains authority to
determine what issues are significant and are transmitted to the preparer for formal (i.e., a
documented, traceable, written record) resolution. The reviewers should provide a technical
basis for the safety significance of an issue through substantiation of its impact on the safety
basis if left unresolved. Each “significant issue” submitted should be accompanied by an
appropriate technical basis (e.g. reference to applicable safe harbor requirements, safety basis
review criteria, or other applicable standards) for its safety significance and whether it needs to
be resolved prior to DSA approval. The review team leader, and subsequently the SBAA, should
rely upon these technical bases in determining the relevance of all issues. The review team
leader and the SBAA should ensure that the set of comments and issues are integrated and
consistent with the requirements for the applicable safety basis documents.
A significant issue is a problem or concern that affects the utility or validity of the safety basis
documentation. Such issues generally involve: (1) release of energy and/or hazardous materials
with significant consequences to the public, worker, or environment; (2) selection of safety
structures, systems, and components (SSCs) and specific administrative controls (SACs), and
ability of these safety controls to perform their intended safety functions; (3) technical errors that
invalidate major conclusions relevant to the safety basis; or (4) failure to cover topical material
required by DOE regulations, directives, and guidance on safety basis.
Section 12
DSAs and other safety basis documents prepared in accordance with 10 CFR Part 830 use the
graded approach in documenting the facility safety basis. The absence of information in a DSA
is not necessarily a significant issue if the absence does not adversely impact the adequacy of the
facility safety basis documentation. For example, standard industrial hazards are not generically
covered in the DSA. But an issue requiring that a standard industrial hazard be included in a
DSA would have a compelling technical basis if a clear case can be made that the industrial
hazard is a potential contributor to a significant release of hazardous material. If an adequate
technical basis for the significance of an issue is not provided, then the review team leader
should not transmit the issue to the DSA preparer as significant and requiring resolution. Such
judgments may be appealed to the approving authority.
DOE-STD-1104-2016
9
Safety basis documents are expected to be technically accurate. Technical errors and
inaccuracies that are identified by review team members should be transmitted as issues for
resolution. Multiple technical errors and significant technical errors can readily rise to the level
of a significant issue that requires resolution.
For issues transmitted to the preparer as significant, the preparer should prepare written
resolutions and submit them to the review team leader. The review team leader then transmits
proposed resolutions to reviewers originating the issues, who should notify the review team
leader if a resolution is considered unsatisfactory. All responses are transmitted through the
review team leader, who schedules and arbitrates the process of resolution. The review team
leader may consider proposed resolutions satisfactory in the absence of timely responses or
adequate technical basis for unacceptability of resolutions by the issue originator. As a matter of
course, the review team leader should ensure that the preparer is formally notified of acceptable
and unacceptable resolutions proposed for significant issues.
Reviewers or the preparer of the safety basis document being reviewed may appeal to the SBAA
the proposed disposition of an issue by the review team leader. The SBAA determines the final
disposition of all issues. Neither a reviewer nor the preparer has veto power over ultimate
resolution or disposition of an issue, and neither need be satisfied with the final resolution. The
review team leader is responsible to document the final disposition of significant issues
(including minority opinions and dissenting views) prior to issuance of the final product.
When professional disagreements arise, employees should first use local processes (e.g.,
discussions with management, review and comment processes, Employee Concerns Programs,
and local DPO processes or their equivalent) to bring attention to a concern. If an employee
concludes, however, that routine work processes did not adequately resolve a concern or an
issue, the employee may use the process defined in DOE O 442.2, Differing Professional
Opinions for Technical Issues Involving Environment, Safety and Health.
Section 13
As stated in10 CFR § 830.202 (c) (3), contractors are required to incorporate in the safety basis
any changes, conditions, or hazard controls directed by DOE. Section 830.207 (d) of the Rule
states that “A contractor may not begin operation of the facility or modification prior to the
issuance of an SER in which DOE approves the safety basis for the facility or modification.”
Documenting directed changes and conditions of approval in the SER provides a way to address
inadequacies in the safety basis that are not significant enough to warrant rejection of the safety
basis, but which need to be addressed. Section 4.10 of this Standard provides guidance on what
constitutes an appropriate condition of approval for DSAs. Section 7.2.12 of this Standard
presents guidance on information to be documented in the SER for each condition of approval.
To ensure adequate tracking and closure of conditions of approval, the DOE site office staff
shall:
• Verify that contractors have a documented process for:
o Tracking conditions of approval to closure (including any required compensatory
measures);
DOE-STD-1104-2016
10
o Verifying satisfactory closure of the condition of approval;
o Notifying DOE when a condition of approval has been satisfied; and
o Managing any conditions of approval until they are closed.
• Ensure that when a condition of approval is satisfied, the basis for closure is documented
in the next update of the DSA and/or TSRs, and the closure of the condition of approval
is noted in the DOE approval of that update; and
• Periodically assess the closure progress and status of conditions of approval, as well as
the contractor tracking process for them.
TSRs identify the limits, controls, and related actions that establish the specific parameters and
requisite actions for the safe operation of a nuclear facility/activity/process. Consistent with 10
CFR § 830.202, the SER may direct changes or impose additional hazard controls to be applied
to the TSRs before operation. SER-directed changes shall be incorporated into the approved
TSRs prior to operation under the approved safety basis.
DOE-STD-1104-2016
11
4.0 APPROVAL OF DOCUMENTED SAFETY ANALYSES
4.1 BASES FOR APPROVAL
The DOE review of the safety basis for nuclear facilities determines whether the safety basis has
been developed in a manner that provides reasonable assurance of adequate protection of
workers, the public, and the environment from adverse consequences, taking into account the
work to be performed and the associated hazards. DOE evaluates the DSA (including DSA
amendments and supplements) by considering the extent to which the DSA (1) adequately
addresses the criteria set forth in 10 CFR § 830.202 and 10 CFR § 830.204, and (2) satisfies the
provisions of the methodology used to prepare the DSA.
The documents (i.e., DOE Orders, Manuals, Guides, and Standards, Nuclear Regulatory
Commission Regulatory Guides and regulations) listed in Table 2 of Appendix A to 10 CFR Part
830, Subpart B, provide approved methodologies for meeting the DSA requirements of 10 CFR
Part 830. These documents are commonly referred to as “safe harbors.”
Section 14
Developed consistent with, and as a companion to these documents, this Standard does not
generally reiterate the provisions of these documents, but may cite specific requirements from
these documents, as convenient for the user of this Standard. If a contractor uses a method other
than a safe harbor method from Table 2 of Appendix A of 10 CFR Part 830, per 10 CFR §
830.204, the contractor is required to obtain DOE approval of the method. If a contractor uses a
safe harbor method to develop the DSA, but does not follow the method completely, per 10 CFR
§ 830.204, the contractor is required to request DOE approval of the method used (with the
specific deviations noted); such DOE approvals are in accordance with DOE-STD-1083-2009, or
successor document.
In accordance with the methodology used, where applicable, DSA review and approval focuses
on the adequacy of the following topical areas to establish the bases for approval of the DSA:
• Base information;
• Hazard and accident analyses;
• Defense-in-depth;
• Safety Structures, Systems, and Components;
• Specific Administrative Controls;
• Derivation of TSRs; and
• Safety Management Programs.
The DSA may be considered adequate when the SBAA concludes that technical justification
exists regarding adequacy of each of these topical areas. Adequacy encompasses technical
accuracy, completeness, and satisfaction of applicable DSA development criteria in the
DOE-STD-1104-2016
12
applicable safe harbor standard. These topical areas and associated criteria established in this
Standard form the foundation for reviewing and documenting DSA and TSR approval in an SER.
For new facilities and major modifications, the review of the DSA and TSRs includes verifying
that the commitments in the PDSA have been met, and the final configuration of the facility is
reflected in the final DSA. The DSA evolves from the PDSA with the addition of the final
analysis of operational hazards and any upset conditions that were not previously considered.
The DSA also documents any changes that were necessary during the construction phase.
4.2 BASE INFORMATION
Base information is the first of the approval bases that should be reviewed and encompasses
elements of DSA preparation, completeness, and general content. Base information is reviewed
for sufficiency to allow assessment of the other approval bases that rely on this information. The
review for sufficiency can range from a simple screening effort to more detailed discussions,
depending on the complexity of the DSA.
Insufficient or incomplete base information in a DSA may prevent further review of the DSA.
Reviewers should require resolution of major discrepancies in base information (e.g., incomplete
site characteristics) before the evaluation proceeds on to the more specific aspects (e.g., hazard
and accident analyses) of the safety basis. For this reason, the SER need only provide a brief
statement as to the adequacy of base information.
As an example, for DSAs adhering to the DOE-STD-3009 format, the review of base
information focuses primarily on evaluation of the Executive Summary, Site Characteristics
(Chapter 1), Facility Description (Chapter 2), and, to some extent, material generic to all DSA
chapters, such as statutes, rules, and orders. In some cases, base information may also be found
in System Descriptions (Chapter 4).
Determining the adequacy of base information rests on being able to reach the following
conclusions:
Section 15
• The facility contractor’s development and approval processes (including personnel
involvement in developing the DSA, management cognizance and acceptance, internal
reviews) demonstrate sufficient commitment to establish the facility safety basis.
• The facility’s mission and scope of operations (i.e., the scope of work to be performed)
for which safety basis approval is being sought are clearly stated and reflected in the type
and scope of operations analyzed in the DSA. For example, a DSA documenting the
safety basis of a spent fuel storage facility whose mission includes size reduction of spent
fuel elements would be unacceptable if the DSA omitted safety analysis of size-reduction
operations.
DOE-STD-1104-2016
13
• A description of the facility’s life-cycle stage, mission, scope of operations, and the
design of safety SSCs3 is presented, including explanation of the impact on the facility
safety basis.
• The description of the site, facility, and operational processes provide a knowledgeable
reviewer with sufficient background material to understand the major elements of the
safety analysis.
• A correlation is established between actual facility arrangements and operations with
those stated in the DSA.
In regard to the bullet above, the correlation may be established by review of facility
walkthroughs undertaken during DSA preparation and review of the final as-built design. In
some cases, however, reviewers may need to conduct their own walkthroughs. A walkthrough
might be advisable, for example, when a significant gap in time separates DSA initiation and
completion. Normally, the review team will not be expected to perform detailed verifications of
facility configuration. The objective of review team walkthroughs is to confirm that the
descriptions provided in the DSA are fundamentally up-to-date and correct.
4.3 HAZARD AND ACCIDENT ANALYSES
Following review of the base information, the DSA review proceeds to evaluation of the hazard
and accident analyses. Determining the adequacy of hazard and accident analyses rests on being
able to reach the following conclusions:
• The hazard analysis includes hazard identification that specifies and estimates the
hazards, both man-made and natural, in terms of type, quantity, and form of radioactive
and other hazardous materials.
• The initial and final hazard category for the facility is determined consistent with
DOE-STD-1027-92,4 Change Notice No. 1. Any differences between the final hazard
category and the initial hazard category are explained.
• The methodology used for hazard analysis is clearly identified and appropriate (e.g.,
techniques chosen and implemented consistent with Center for Chemical Process Safety’s
Guidelines for Hazard Evaluation Procedures), including supportable input assumptions
and criteria, and correct application of analytical tools used as part of the process.
• The hazard analysis evaluates all activities for which approval is sought, is consistent in
approach with safe harbor methodologies or approved alternate methods, and identifies
preventive and mitigative hazard controls for the spectrum of hazards evaluated.
3 Safety SSCs are defined in 10 CFR § 830.3 as the combination of safety class SSCs and safety significant SSCs.
4 Nuclear Safety Technical Positions 2002-2, Methodology for Final Hazard Categorization for Nuclear Facilities
Section 16
from Category 3 to Radiological, and 2007-1, Technical Position on the Requirement in DOE 0 420.1B to Use
National Consensus Industry Standards and the Model Building Codes, provide supplemental guidance as an aid
in proper implementation of DOE Standard 1027.
DOE-STD-1104-2016
14
• The hazard analysis evaluates normal, abnormal, and accident conditions, including
natural and man-made external events, and identifies the energy sources or processes that
might contribute to the generation or uncontrolled release of radioactive and other
hazardous materials. The hazard analysis results are clearly characterized in terms of
public safety, defense-in-depth, co-located worker safety, facility worker safety, and
environmental protection. The logic behind assessing the results in terms of safety
significant SSCs, SACs, and designation of TSRs is understandable and internally
consistent.
• Accident analysis is performed for an adequate set of design/evaluation basis accidents
(D/EBAs) having unmitigated offsite consequences that have the potential to challenge
the EG.
• The accident analysis methodology is clearly identified and appropriate, including
identification of initial conditions and assumptions. The technical basis for source term
values is provided, valid, and appropriate for the physical situation being analyzed. The
completeness and level of detail in the technical basis should increase as the parameters
depart from the default or bounding values described in Part 830’s safe harbor methods.
Supporting calculations and technical documents are identified, where appropriate, and
reviewed for critical aspects of safety controls, where appropriate.
• The modeling protocol, if used to support site/facility specific values in atmospheric
dispersion modeling (see Section 3.2.4.2 of DOE-STD-3009-2014), meets the criteria and
guidance provided in DOE-STD-3009-2014, and an adequate technical basis is provided
for the receptor locations, meteorological data, modeling tools, and modeling parameters.
• Probabilistic risk assessments, related tools, and probabilistic calculations (if used) are
used in a manner consistent with the applicable provisions of DOE-STD-1628-2013,
Development of Probabilistic Risk Assessments for Nuclear Safety Applications, and
supplements the qualitative/deterministic processes for hazard assessments and hazard
control development.
• Accident analysis clearly substantiates the findings of hazard analysis for the
design/evaluation basis events and demonstrates the effectiveness of safety class SSCs, if
needed to prevent or reduce the likelihood of accidents or mitigate dose consequences
below the EG. (Note: If the safety class SSCs do not reduce mitigated dose consequences
below the EG, see Section 4.9 of this Standard.)
• Safety class SSCs, SACs and associated TSRs have been identified for preventing and/or
mitigating events that exceed the EG.
• If required, safety significant SSCs, SACs, and associated TSRs have been identified for
preventing and/or mitigating events that may cause worker fatalities or serious injuries;
may potentially exceed the worker/co-located worker radiological consequence
thresholds or the applicable “significant” public and co-located worker toxicological
thresholds; or are determined to provide major contribution to defense-in-depth.
DOE-STD-1104-2016
15
The facility worker’s mobility or ability to react to hazardous conditions is not used as
the sole or primary basis for determining facility worker impacts.
Section 17
• Where planned operational improvements are identified in the DSA, interim controls are
identified, if required to provide adequate protection, and assigned appropriate safety
classification.
• Beyond Design/Evaluation Basis Accidents are adequately considered in the DSA. If
mitigated off-site dose estimates for postulated D/EBA accidents are close to the EG,
impacts from a spectrum of accidents is presented (i.e., as opposed to only evaluating
seismic hazards) along with a discussion of controls and actions available to mitigate
consequences. Note: For more complex facilities, it is acceptable for these accidents to
be described in a separate, controlled document that is referenced in the DSA.
The goal of the review is to ensure that the safety basis is comprehensive relative to hazards
presented and is based on a consistent, substantiated logic. Reviewers should use the approved
methodology used in developing the DSA (i.e., 10 CFR Part 830 safe harbor standard or
approved alternate methodology) as the primary reference to support their review.
4.4 DEFENSE-IN-DEPTH
Defense-in-depth is the next aspect of hazard controls to be reviewed. Defense-in-depth is a
fundamental approach to hazard control for nuclear facilities that is based on having several
layers of protection to prevent the release of radiological or hazardous materials to the
environment. These protective layers are normally redundant and independent of each other to
compensate for unavoidable human and mechanical failures, so that no single layer is exclusively
relied upon. The layers of defense could consist of safety class or safety significant controls that
are protected by a TSR, administrative controls, safety management programs, and other SSCs.
Determining the adequacy of defense-in-depth rests on being able to conclude that postulated
events and accidents are controlled with appropriate levels of defense-in-depth that are applied
such that several layers of protection are used to prevent or mitigate the release of radiological or
hazardous materials to the environment.
4.5 SAFETY STRUCTURES, SYSTEMS, AND COMPONENTS (SSCs)
Identification of safety SSCs is a product of the hazard and accident analyses. Determining the
adequacy of safety SSCs rests on being able to reach the following conclusions:
• The safety SSCs identified and described are consistent with the logic presented in the
hazard and accident analyses.
• Safety functions for safety SSCs are defined with clarity and are consistent with the bases
derived in the hazard and accident analyses.
• Safety systems are clearly described to include essential components needed to meet the
safety function. The boundaries of safety SSCs and support systems are clearly defined
and interfaces with other SSCs are described.
DOE-STD-1104-2016
16
• Support SSCs are clearly described and designated as safety class or safety significant for
cases where their failures prevent safety SSCs or SACs from performing their safety
functions.
• Functional requirements and performance criteria are defined such that, when met, they
ensure that the safety functions can be performed when needed.
• A system evaluation demonstrates that the system can meet applicable performance
criteria thereby ensuring the functional requirements are met under postulated accident
conditions (e.g., elevated temperatures and pressures) and the required safety functions
are fulfilled. The evaluation contains an engineering evaluation with a supportable basis
such as one of the following methods:
Section 18
o Providing a technical basis that includes an evaluation against the code of record,
to the extent known, and augmented as needed with calculations, performance
tests, or reliability evidence from operating history or industry databases;
o Comparing the safety SSC design attributes to DOE O 420.1C (or applicable
successor document) design requirements, and associated codes and standards that
are applicable, to demonstrate compliance; or,
o Demonstrating that the existing SSCs satisfy equivalent design requirements of
current design codes and standards.
• Key assumptions are identified so that appropriate TSR protection can be developed or
derived (such as in limiting conditions of operations (LCOs), design features, and SACs).
4.6 SPECIFIC ADMINISTRATIVE CONTROLS
SACs are administrative controls selected to prevent and/or mitigate specific accident scenarios
and have safety importance equivalent to engineered controls that would normally be classified
as safety SSCs. Engineered controls (safety SSCs) are preferred over SACs for these functions;
thus, SACs should only be selected if engineered controls cannot be identified to serve these
functions or are not practical.
Determining the adequacy of SACs rests on being able to reach the following conclusions:
• The SACs identified and described are consistent with the logic presented in the hazard
and accident analyses.
• Safety functions for SACs are defined with clarity and are consistent with the bases
derived in the hazards and accident analyses.
• The SACs are readily understood and can be effectively implemented. The supporting
SSCs and other administrative controls whose failure would result in an inability to
complete the required SAC safety actions(s) are identified at the same level of safety
significance as the SAC, or justification provided if not so designated.
DOE-STD-1104-2016
17
4.7 DERIVATION OF TECHNICAL SAFETY REQUIREMENTS
Hazard controls are derived to eliminate, limit, or mitigate hazards. The controls generally are
safety SSCs, SACs, or commitments to safety management programs, which are ultimately
included in TSRs. TSRs cover the most significant preventive and mitigative features identified
in the hazard and accident analyses.
Determining the adequacy of the derivation of TSRs rests on being able to reach the following
conclusions:
• TSRs are identified to ensure adequate protection of workers, the public, and the
environment.
• The bases for deriving TSRs are identified and described in the hazard and accident
analyses and safety SSC chapters (which include SACs) and are consistent with the logic
and assumptions presented in the analyses.
• The bases for deriving safety limits, limiting control settings, LCOs, surveillance
requirements, and administrative controls are provided as appropriate.
• The facility modes, if applicable, are defined and those associated with TSRs are
consistent with the hazard analysis and accident analysis.
• The process for maintaining the TSRs current at all times and for controlling changes is
defined.
4.8 SAFETY MANAGEMENT PROGRAMS
Section 19
Safety management program characteristics encompass the elements of institutional programs
and facility management that are necessary to ensure safe operations based on assumptions made
in the hazard and accident analyses. While these elements are required to be addressed in the
DSA, generic descriptions of these institutional programs should not be duplicated in the DSA if
they can be referenced in Integrated Safety Management System documents or in site-wide
manuals. These institutional programs include quality assurance, procedures, maintenance,
personnel training, conduct of operations, emergency preparedness, fire protection, waste
management, radiation protection, and criticality safety, and may include other programs unique
to the facility. Identification of safety management program characteristics and credited
attributes is a product of hazard and accident analyses, designation of safety SSCs and SACs,
and derivation of TSRs.
Determining the adequacy of safety management program characteristics rests on being able to
reach the following conclusions:
• The major programs needed to provide programmatic safety management are identified.
• Basic provisions of identified programs are noted, and references to facility or site
program documentation are provided.
DOE-STD-1104-2016
18
• Key characteristics of programs that are identified in the hazard analysis are identified in
safety management program descriptions. Such key characteristics are important to safe
operation of the facility, but not at a level that requires safety significant classification.
The review of safety management programs is normally performed at the site-wide level and
a reference to the site-wide review is sufficient to support the DSA review. The acceptance of
safety management program characteristics in the DSA does not constitute acceptance of the
adequacy of program compliance with DOE directives (which typically can be accomplished
only by a detailed compliance review of each of the programs). In the DSA context, detailed
reviews of the adequacy of safety management programs only need to be performed for safety
management programs that are specific to the facility.
4.9 EXISTING FACILITIES WITH MITIGATED OFFSITE CONSEQUENCE
ESTIMATES OVER THE EG
This section provides specific approval bases for rare situations where safety class controls are
not provided to prevent or mitigate offsite doses below the EG.
For proposed changes to an existing facility safety basis where no viable control strategy exists
to prevent or mitigate the consequence of one or more of the accident scenarios from exceeding
the EG, DOE shall verify that information is included in the proposed safety basis change that
addresses the requirements described in Section 3.3.1 of DOE-STD-3009-2014.
The following criteria should be used to judge technical adequacy of DSA information:
• Accidents that cannot be mitigated below the EG or prevented, are explicitly identified,
including the likelihood of the event(s) and the mitigated consequences associated with
the event(s).
• Accidents likelihood and consequences are determined in accordance with the DSA safe
harbor methodology (e.g., Section 3.2 of DOE-STD-3009-2014). This includes source
term estimates, dispersion analysis methodology, and dose consequence assumptions.
Section 20
• Mean or best estimate values used for source-term and dispersion input parameters that
are part of comparative analyses (e.g., as described in DOE-STD-3009-2014, Section
3.3.1, bullet #2) have a valid technical basis that includes logical assumptions that are
based on experiments, tests, or sound engineering judgment. The analysis describes the
significant contributors to uncertainties in both the likelihood and consequence
evaluations. The mean or best estimate calculation is used to provide perspective
regarding the degree of conservatism that is imbedded in the consequence calculation.
• The reliability and adequacy of credited controls is addressed (e.g., consistent with
DOE-STD-3009-2014 system evaluation requirements for safety class SSCs, as
applicable).
• Controls considered (SSCs and SACs) but not identified as safety class that could further
reduce the likelihood and/or consequences of the associated accident(s) are described in
DOE-STD-1104-2016
19
the DSA. The impact of these controls on accident mitigation, as well as the rationale for
not classifying these controls as safety class should be presented. Discussions of
potential failure modes of SSCs and any relevant cost/benefit results are included.
• Planned operational or safety improvements are presented and include potential facility
modifications, removal of MAR, packaging of MAR into containers, operational
restrictions, and/or additional compensatory measures, and associated schedules, to
further reduce the likelihood and/or mitigate consequences of an accident.
• A qualitative or semi-quantitative comparison of the facility risk from identified
scenarios and cumulative facility risk (for all facility operations) estimate for facility
accidents (including the results in response to the second bullet) is presented along with a
comparison to the quantitative safety objectives provided in DOE Policy 420.1. A
discussion of the level of risk and the basis why this risk is acceptable is provided, taking
into account an evaluation of available alternatives, the benefits to the public of the
alternatives, and the costs to the public of the alternatives.
The level of detail for the analysis above may be graded based on the remaining operating life of
the facility and the extent of deviation from the EG. The DOE review should consider the best
available mission statements related to facility operations and determine whether there is a high
likelihood that projected estimates of remaining operational life are supported and commensurate
with details provided in the DSA. Likewise, the extent of deviation from the EG for mitigated
consequences estimates should be explicitly addressed by the DOE review team and discussed in
the SER as part of the approval basis. Planned operational or safety improvements, including
compensatory measures, should be pursued where the deviation from the EG is significant (such
as where the mitigated offsite dose estimate is more than two to three times greater than the EG),
the remaining life is significant (such as more than 1-3 years), and the likelihood is significant
(such as more often than 1 in 106 years). Compensatory measures should be commensurate with
the significance of the deviation from the EG, the likelihood of accident(s), and the length of
time needed to resolve the condition.
Section 21
The SBAA for safety basis documents that include mitigated doses above the EG shall be at the
PSO level, at a minimum. The SBAA shall obtain concurrence from the CTA and consult with
the Office of Environment, Health, Safety and Security on the technical adequacy of the safety
basis document submittal. As with other changes, DOE will prepare an SER to document its
technical review of the information provided and its decision regarding continued operation. See
Section 7 of this Standard for SER contents discussion. The requirement for SBAA at the PSO
level only applies to DSAs, amendments, TSRs, and other safety basis documents related to the
“over the EG” scenario and controls, including DSA annual updates that affect the associated
safety basis content required by DOE-STD-3009-2014, Section 3.3.1, such as planned safety
improvements and associated schedules. Other safety basis changes may be approved in separate
safety basis submittals, as delegated.
4.10 CONDITIONS OF APPROVAL
Conditions of approval should be used to document any changes, conditions, or hazard controls
directed by DOE. Editorial issues such as incorrect punctuation and misspelling that do not
DOE-STD-1104-2016
20
change the meaning or technical content of a statement should not be handled through conditions
of approval. Conditions of approval also should not be used to approve DSAs and TSRs with
fundamental flaws. Large numbers of conditions of approval for a single DSA may indicate that
the DSA is fundamentally flawed and should prompt a review to identify issues that DOE will
require to be corrected prior to approval of the DSA. The SBAA should not approve conditions
of approval for extended periods of time. A defined closure date or milestone shall be identified
in the condition of approval. If a condition is intended to be applied for an extended period of
time, the DSA should reflect that condition as part of the analysis. Conditions of approval may
identify compensatory measures that are required for limited periods until the conditions of
approval are closed.
Conditions of approval from prior SERs should be reviewed during reviews of updates to the
safety basis documents. Such conditions of approval should be closed or an explanation
provided in the SER as to why they remain open.
Conditions of approval may not be used to allow the facility/activity/program to be outside of the
approved safety basis or to be inconsistent with a consensus code/standard, law or other
requirements.
Examples of situations where conditions of approval would be appropriate for DSA and TSRs
are:
• Use of a fire watch where a fire barrier is required by the safety analysis but is not yet
installed, and
• Use of personal protective equipment such as respiratory protection to mitigate any
exposure to workers doing glovebox repackaging operations for a defined period, until
a design correction identified in the DSA can be completed.
Fundamentally, the DSA is intended to demonstrate that proposed activities have been
thoroughly described and analyzed and that the hazards have been adequately identified. The
DSA establishes the linkage between the individual hazards identified and the final control set
that addresses each hazard. The functions of the controls that are relied upon for safety are
clearly documented and demonstrated to be adequate for the bounded hazards that they are
intended to address. The selected controls are documented as capable of providing the credited
safety functions and appropriately captured in the TSRs.
Section 22
The DSA, TSRs, SER, and conditions of approval together provide an acceptable safety
envelope for the facility, activity, or program. While individual instances of a shortcoming in
one of these areas, such as the need for an additional control, may be addressed in a condition of
approval, a fundamental weakness in the processes used to perform the hazard analysis and
accident analysis would render the DSA unacceptable.
Approval of the DSA and TSRs signifies that DOE has reasonable assurance that the nuclear
facility can be operated safely and in a manner that adequately protects workers, the public, and
the environment.
DOE-STD-1104-2016
21
4.11 REJECTION OF A DSA
The following are examples of issues that would preclude DOE approval of the DSA and hence
should not be addressed through conditions of approval:
• There is insufficient information to document the conclusion that there is reasonable
assurance of adequate protection of the worker, the public, and the environment.
• The DSA does not meet the regulatory requirements of 10 CFR Part 830, and associated
safe harbor methodology, and does not have an approved exemption in accordance with
10 CFR Part 820, Subpart E.
• Significant issues were identified during the acceptance review that would prevent
conducting a successful technical review.
• The base information contained in the DSA is insufficient to describe the activities,
processes, or systems to enable the hazard analyst to identify a complete set of hazards
for the covered facility, activity, or program.
• The hazard analysis is incomplete or has significant errors (e.g., there are missing
hazards; the response is incomplete, unavailable, or misapplied).
• The accident analysis is incomplete or has significant errors (e.g., a scenario does not
bound the hazard from the hazard analysis; there are incorrect calculations supporting the
accident analysis conclusions).
• Deficiencies related to hazard controls that cannot be remedied within conditions of
approval and directed changes to TSRs.
The SBRT should identify such issues as early as possible in the DSA review, confirm their
existence, and, if confirmed, provide a recommendation to the SBAA to return the DSA for
additional contractor effort. The SBAA should return the rejected DSA to the contractor for
action.
DOE-STD-1104-2016
22
5.0 APPROVAL OF TECHNICAL SAFETY REQUIREMENTS
5.1 MANAGEMENT AND COORDINATION
DOE reviews of TSRs are generally conducted in coordination with DSA reviews, and by many
of the same team members. This approach provides an economy of effort because team
members, by virtue of their familiarity with the DSA, have an understanding of the commitments
made in the DSA that need to be reflected in the TSR. The discussions in Section 3 of this
Standard relative to management and coordination of DSA reviews are equally applicable to the
TSR review process. The review plan should address both DSA and TSR reviews. Because the
TSRs implement commitments made in the DSA, approvals and implementation of both the
DSA and TSRs should be coordinated.
DOE G 423.1-1B, Implementation Guide for Use in Developing Technical Safety Requirements,
provides guidance on how to meet the requirements for TSRs found in 10 CFR § 830.205. DOE
reviews of TSRs include focus on whether the TSRs format and content are consistent with DOE
G 423.1-1B.
5.2 BASES OF APPROVAL
Section 23
Review and approval for the TSR document is based on the TSR provisions, which include
design features, safety limits, operating limits (i.e., limiting control settings and LCO),
surveillance requirements, and administrative controls. DOE review and approval of a TSR
document includes a disciplined analysis and tracing of commitments to hazard controls in the
DSA to appropriate provisions that implement these controls in a TSR document.
Determining the adequacy of the TSR provisions rests on being able to conclude that:
• TSR provisions are appropriate and consistent with the DSA; and,
• TSRs provisions are clear, implementable and consistent with DOE G 423.1-1B (or
successor document in site contract).
The sources of information in a DSA regarding TSRs are the hazard analysis (including
description of hazard controls); the description of safety SSCs; the classification of these SSCs as
safety class, safety significant, or other important SSCs; the description of the functional
requirements for the safety SSCs; the description and functional requirements for SACs; the
derivation of TSRs; and the descriptions of the safety management programs.
5.3 TSR CONSISTENCY WITH THE DSA
Review criteria to assess consistency are provided below:
• TSR requirements are based on functional requirements described in the DSA.
• Safety SSCs are addressed specifically in TSR provisions. Active, safety class SSCs may
have a safety limit and a limiting control setting associated with them, and will usually
have a LCO and a surveillance requirement. An active safety significant SSC may have
DOE-STD-1104-2016
23
a LCO and surveillance requirement and/or specific provisions of a maintenance
management program associated with its Technical bases for limiting control settings,
LCO, and surveillance requirements in the Bases appendix of the TSR should be
reviewed for adequacy. All of these provisions are directed at ensuring that the safety
function of the SSC will be protected.
• Passive features are designated as “Design Features” in the TSR. A crosscheck between
DSA-identified important design features and the Design Features section of the TSR
should be conducted to ensure consistency. Passive design features may also require
surveillance and maintenance provisions to ensure they continue to meet designated
safety functions (e.g., erosion of overburden for Pantex Cells).
• When SACs are used, they are controlled through the TSR. DOE-STD-1186 specifies
the TSR provisions that are acceptable to use for SACs. The first involves using the
conventions for LCO and associated surveillance requirements (e.g., material-at-risk
limits). The second method available to incorporate SACs into a TSR document is to
identify the specific requirement/action in a special section in the Administrative Control
section of the TSR. This format may be appropriate when it is essential that the SAC be
performed every time and without any delay when called upon (e.g., hoisting limits for
nuclear explosives) or when definitive program requirements for specific activities can be
established.
• The administrative controls section of the TSR addresses commitments to implement
safety management programs identified in the DSA as important to the facility safety
basis. Hazards analyses may invoke particular provisions of safety management
programs, such as emergency preparedness, criticality safety, procedures, and training.
Section 24
• If DOE conditions of approval are identified for the DSA, the review team ensures that
TSR provisions have been developed, as appropriate, to provide assurance of the
identified safety functions.
5.4 TSR CONSISTENCY WITH DOE G 423.1-1B
The second aspect of adequate TSRs is consistency with guidance provided in DOE G 423.1-1B
(or successor document in site contract). Review criteria from this Guide needed to reach this
conclusion are provided below for various sections of the TSR. The criteria should be followed
to the extent they are applicable to the TSR being reviewed.
• Section 1, Use and Application. Terms that operators and other facility staff need to
understand the TSRs are defined. Definitions should be clear and concise. Operational
modes are clearly demarcated. Frequency notations used in surveillances or elsewhere
follow standard definitions and usages given in DOE G 423.1-1B.
• Section 2, Safety Limits. Safety Limits are consistent with the DSA accident analysis
and describe the parameters being limited. Limits are stated in measurable terms and
have a defined facility mode or other conditions under which they are applicable.
DOE-STD-1104-2016
24
Actions required to be taken if a Safety Limit is exceeded are described and, if taken, will
achieve a safe and stable state.
• Section 3/4, Limiting Control Settings, Limiting Conditions for Operations, and
Surveillance Requirements. Operability requirements for active safety SSCs, or operator
actions for SACs (i.e., where specified in LCO format), are unambiguous and concise.
LCO statements are precise and state the lowest functional capability or performance
level required for safe operation. Instrument setpoints/values properly account for
uncertainties (e.g., derivation is consistent with ANSI/ISA 67.04.01, Setpoints for
Nuclear Safety Related Instrumentation). Facility modes and process areas are specified
and ensure applicability of LCOs during operations in which accidents for which they are
credited in the DSA are possible. Actions are clear and simple, ensure a safer condition
upon implementation, and specify a completion time that allows for safe and timely
implementation. Surveillance requirements are established for SSC operability that
specifies the requirements necessary to ensure compliance with the LCO (e.g., specific
values, limits, etc., should be stated in the Surveillance Requirements). A frequency of
performance is established for each Surveillance Requirement with a sound technical
basis (e.g., vendor information, past performance history, and consistent with supporting
uncertainty analysis).
• Section 5, Administrative Controls. Administrative provisions and commitments are
provided related to organization and management, procedures, qualifications and training,
record keeping, review and assessments, reporting, safety management programs, and
actions relevant to deviations from TSRs. Facility management responsibilities should be
clear and encompass actions necessary to ensure safe operation. Minimum staffing
requirements are specified where required based on the safety analysis. Safety
management programs include commitments to important attributes emphasized in the
DSA (e.g., In-Service Surveillance and Maintenance for design features). SACs having
directed actions are identified and meet the expectations of the applicable DOE technical
standard (DOE-STD-1186-2016, or other approved document).
Section 25
• Section 6, Design Features. Features that must be protected based on the safety analysis
are included. The description of design features provides sufficient detail related to
materials of construction, important dimensions, configuration, and physical arrangement
such that important attributes needed to meet safety functional requirements are protected
in the TSR.
• Bases Appendix. Bases are provided for Safety Limits, Limiting Control Settings, LCOs,
and associated Surveillance Requirements. The bases provide supportable statements and
reasoning. This includes references back to safety analyses to support selected operating
limits and numeric values, conditions, surveillances, and LCO response actions.
DOE-STD-1104-2016
25
6.0 APPROVAL OF OTHER SAFETY BASIS RELATED DOCUMENTS
This section provides criteria and guidance for approval of documents that support the
maintenance of safety basis or provide analysis and controls that becomes part of or supports the
safety basis for unique situations.
6.1 UNREVIEWED SAFETY QUESTION PROCESS PROCEDURE
Title 10 CFR § 830.203 requires DOE approval of the contractor’s procedure for carrying out
USQ determinations (USQDs). Changes to the contractor USQ process procedures require DOE
approval. DOE may approve the procedure by an SER or by letter with a basis of approval. The
format and content requirements and guidance in Section 7 of this Standard should be tailored
for an SER or basis of approval used to approve a USQ procedure.
The basis for approval of the USQ procedure shall address the expectations from the DOE G
424.1-1B, Implementation Guide for Use in Addressing Unreviewed Safety Question
Requirements (or successor document in the site contract).
6.2 DOCUMENTS THAT RESULT FROM POSITIVE USQ DETERMINATIONS
Title 10 CFR § 830.203 requires contractors to perform USQDs and notify DOE when the
contractor discovers or is made aware of a potentially inadequate safety analysis (PISA). Title
10 CFR § 830.203 also requires DOE approval prior to the contractor taking any action(s) that
have been determined to involve a USQ. Since a “positive” USQD indicates a situation that is
not within the current DOE-approved safety envelope (i.e., a USQ), that situation or action(s) is
required to be evaluated in accordance with 10 CFR Part 830 and approved by DOE. Positive
USQDs may result from either proposed changes or from PISA situations.
Proposed changes resulting in a positive USQD require a safety basis revision or amendment
prior to implementation and associated DOE approval in accordance with Section 4 of this
Standard. For proposed changes to an existing facility safety basis where no viable control
strategy exists to prevent or mitigate the consequences of one or more accident scenarios from
exceeding the EG, DOE shall verify that information is included in the proposed safety basis
change that addresses the requirements in Section 3.3.1 of DOE-STD-3009-2014 (See Section
4.9 of this Standard for further information).
Resolution of a PISA requires submittal of an ESS, and often submittal of a JCO and/or revisions
(e.g., amendments) to previous safety basis documents. ESS and JCO submittals are documents
that are temporary in nature.
6.2.1 Evaluation of the Safety of the Situation
Section 26
Title 10 CFR § 830.203 requires contractor submittal of the ESS prior to removing any
operational restrictions initiated to place or maintain a facility in a safe condition subsequent to
the contractor discovering or being made aware of a PISA. The ESS does not require DOE
approval in accordance with 10 CFR § 830.203; however, DOE should review the ESS in a
timely manner and direct the contractor if DOE disagrees with the removal of the operational
restrictions.
DOE-STD-1104-2016
26
DOE should formally approve ESSs for PISAs that result in a positive USQD. DOE review of
the ESS should focus on the adequacy of the contractor’s analysis of the impact of the PISA on
the safety of the facility and the capability of the operational restrictions/controls to mitigate the
hazards and to compensate for any potential decreases in the facility safety caused by the PISA.
The approval authority for the DOE should be at the same level as the Safety Basis Approval
Authority level for the facility.
When the ESS includes a change to the safety basis, DOE may approve the ESS using a SER or
by letter with a basis of approval. The format and content requirements and guidance in Section
7 of this Standard should be tailored for a SER or basis of approval used to approve the ESS. The
bases for approval of the ESS shall address the expectations from the DOE G 424.1-1B (or
successor document in the site contract) as described below.
For an updated ESS that is submitted in lieu of a JCO, the bases for approval of the ESS shall
address the expectations for a JCO as described in DOE G 424.1-1B, or successor document.
6.2.2 Justification for Continued Operation
A JCO is a safety basis document described in DOE G 424.1-1B. It is a mechanism by which a
contractor may request that DOE review and approve a temporary change to the facility safety
basis that would allow the facility to continue operating in view of a specific and unexpected
situation, considering the safety significance of the situation and any compensatory measures
being applied during this period. A JCO is associated only with situations where the PISA
USQD is positive. For JCOs to an existing facility safety basis where no viable control strategy
exists to prevent or mitigate the consequences of one or more accident scenarios from exceeding
the EG, DOE shall verify that information is included in the proposed safety basis change that
addresses the requirements in Section 3.3.1 of DOE-STD-3009-2014 (see Section 4.9 of this
Standard for further information).
DOE may approve a JCO using a SER or by letter with a basis of approval. The format and
content requirements and guidance in Section 7 of this Standard should be tailored for a SER or
basis of approval used to approve the JCO. The bases for approval of the JCO shall address the
expectations from the DOE G 424.1-1B (or successor document in the site contract) as described
below.
6.3 DOWNGRADES IN FACILITY HAZARD CATEGORIZATION TO “BELOW
HAZARD CATEGORY 3” STATUS
In some cases, a DOE facility may initially be categorized as a Hazard Category 2 or 3 facility
based on DOE-STD-1027-92, but subsequently, based on the results of a facility-specific hazard
analysis and final categorization (performed in accordance with the provisions of
DOE-STD-1027-92), the facility may be determined by the contractor to be a “Below Hazard
Category 3” nuclear facility. In these cases, DOE shall review and approve the final
categorization based on facility-specific hazard analysis to confirm that the hazard analysis and
final categorization are accurate. Nuclear Safety Technical Position 2002-2, Methodology for
Final Hazard Categorization for Nuclear Facilities from Category 3 to Radiological, may be
Section 27
DOE-STD-1104-2016
27
used as guidance for how a Hazard Category 3 facility or activity can be demonstrated to be
below Hazard Category 3 (i.e., radiological) in final hazard categorization.
The following review criteria should be used in judging adequacy of such final hazard
categorization downgrades below Hazard Category 3:
• Base information is sufficient to understand and analyze the facility and its proposed
operations;
• Final hazard categorization of the facility is based on analyses of an unmitigated release
of the available radioactive materials;
• The hazard analysis is comprehensive in identifying the hazards of the facility and
applies appropriate hazard analysis techniques used to support final hazard
categorizations;
• Radioactive material inventory is bounding;
• Radioactive material physical form and dispersibility are considered under the full range
of potential unmitigated accident conditions that would be expected to occur within the
facility;
• Bounding airborne release fractions and respirable fractions are used from
DOE-HDBK-3010-94, Airborne Release Fractions/Rates and Respirable Fractions for
Nonreactor Nuclear Facilities, unless a different value is provided in an applicable
standard or is otherwise technically justified, to compare against base assumptions of
DOE-STD-1027-92; and
• Assumptions used to reduce the inventory at risk, such as facility segmentation, are
technically justified.
In other cases, existing nuclear facilities may be downgraded to below Hazard Category 3 if the
gross inventory of radiological materials are reduced below the DOE-STD-1027-92 threshold
quantities due to a change in mission, de-inventory, or other changes. Because these changes
alter the initial hazard categorization, DOE review and approval by the SBAA are not required.
Such facilities are no longer required to implement the requirements of 10 CFR Part 830, Subpart
B, Safety Basis Requirements; however, administrative controls might be needed to maintain the
new hazard categorization. In such downgrade cases, the contractor will typically notify DOE of
a change in Hazard Category, and when so notified, DOE should provide an acknowledgment to
the contractor, and may perform a verification of facility status prior to this acknowledgment.
DOE-STD-1104-2016
28
7.0 SAFETY EVALUATION REPORTS
7.1 GENERAL DISCUSSION
The DOE review process results in the generation of an SER that becomes part of the facility’s
safety basis. The SER for a given facility or operation shall document: (1) the conduct of an
appropriate review of the safety basis document (e.g., PDSA, DSA, or TSRs); (2) the bases for
approving these documents (see Sections 4, 5, and 6 of this Standard for approval bases for
different safety basis documents); and (3) any conditions of approval. Approval of the DSA
signifies that DOE has reasonable assurance that the nuclear facility can be operated safely and
in a manner that adequately protects workers, the public, and the environment.
If it is a… Then document the
evaluation in a…
PDSA
Safety Evaluation Report
(SER) DSA
TSR
Section 28
The SER is developed specifically to document acceptance of the PDSA, DSA, and TSRs.
Therefore, significant issues concerning these documents are typically resolved and incorporated
in the PDSA, DSA, and TSRs before the final SER is prepared. An analysis that was not
performed during preparation of the PDSA, DSA, and TSRs, but is determined to be required to
complete the review is also documented independently of the SER. Only statements pertinent to
accepting the facility basis are included in the SER. In accomplishing this, informed judgment
and discretion are used to focus the SER on facts that clearly reflect the actual conditions of the
facility safety basis. The SER does not need to repeat in wholesale fashion material contained in
the PDSA, DSA, and TSRs
The SER is intended to provide an overall summary of the methodology, assumptions, bases,
conclusions, and commitments in the PDSA, DSA, and TSRs rather than a total reanalysis
(i.e., independent verification and validation) of those activities addressed in these documents.
During the review process, limited independent verification and validation may be performed;
for example, in cases where (1) there may be significant questions about the validity of the
original analysis, (2) where the risks are significant, and/or (3) the analysis is critical to the
overall conclusions in the safety basis document being reviewed. However, significant
discrepancies should be resolved as part of the development effort for the safety basis document
and, if deemed appropriate, only briefly documented in the SER. The resolution of such
significant discrepancies should not be deferred to conditions of approval. The SER clearly
states any conditions of approval that impose additional commitments to which facility
management will be required to adhere beyond those already documented in the safety basis
document being reviewed. In general, conditions that could be incorporated into the body of
these documents are so incorporated during the review process as prompted by issue resolution
(as opposed to being addressed in the SER and potentially invalidating portions of the safety
DOE-STD-1104-2016
29
basis document being reviewed). See Sections 4.9 and 7.2.12 for additional discussion of
conditions of approval.
Approval statements addressing specific areas of the safety basis are augmented with brief
summaries of the most significant facility-specific points in those areas to provide a basic context
to understand what is being approved. In stating the adequacy of the approval bases, it may also
prove advantageous and/or warranted for the SER to discuss areas of concern or issues with
significant ramifications for facility operations. Generally, these issues will have been resolved
and any inquiries into them will have been completed during the review process. Any discussion
of issues in the SER should be on a summary level and directed towards clarifying some specific
aspect of approval or demonstrating understanding of some aspect of the facility safety basis.
In the case of DSAs and TSRs, if the SER imposes a condition of approval (e.g., additional
compensatory measures, alterations of stated commitments) on the facility safety basis
documented in the DSA and TSRs, then the SER necessarily modifies that facility safety basis.
In such cases, conditions cited in the SER become part of the facility safety basis. Therefore,
a facility safety basis is composed of an approved DSA and TSRs, modified as necessary by the
SER to reflect DOE-imposed conditions of approval. The SER or memorandum stating the
conditions becomes part of the facility’s safety basis. Specification of conditions in the SER not
currently in place in these documents should identify an expected schedule for completion.
Section 29
7.1.1 Review of PDSAs
The SER for a PDSA may also direct changes to the PDSA, as well as add conditions of
approval, although this should be done only when absolutely necessary. One of the purposes of
the PDSA and its revisions is to keep DOE engaged in the design activities of the project and
aware of any significant changes to the design as they occur to ensure DOE is in agreement with
current and proposed design activities. The PDSA also serves to document final design concepts
that support the adequacy of control suite selection that ensure adequate protection of the public
and the workers. Section 8.6 of this Standard provides the approval bases to be used for PDSAs.
7.1.2 Review of Safety Basis Changes and DSA Annual Updates
Revisions of DSAs and TSRs, including DSA annual updates undergo review and approval by
DOE. Review and approval of revisions and annual updates are a matter of endorsing the
incorporation of changes in the safety basis since the last approval rather than performing a new
assessment of the previously approved safety basis documents. Timely DOE review and
approval of annual contractor DSA and TSR submissions is essential to support the annual
review process and should generally be completed within 90-120 days of submission. A longer
review period may be necessary to perform an adequate technical review for updates and
facilities with high levels of complexity (e.g., the High Flux Isotope Reactor facility).
Review of DSA revisions, addenda, and updates should consider the cumulative effect of
changes to the DSA and their impact on usability and accuracy of USQ reviews. For example, if
the safety basis for a facility is contained in multiple documents, with complex interactions and
overlaps, this packaging of the safety basis could potentially compromise the effectiveness and
the efficiency of USQ reviews.
DOE-STD-1104-2016
30
SERs document the bases for approving revisions, including annual updates of DSAs and TSRs.
An SER for a revision typically does not provide the complete basis of approval for that DSA
and TSRs and only provides the basis of approving changes in the provisions resulting from
the revision. Therefore, SERs for revisions are appended to the SER, documenting the last
comprehensive determination for the basis for approval of the DSA and TSRs. Collectively, an
SER and its appendices provide the complete basis of approval for any given DSA and TSRs.
An SER without appendices is generated upon the next comprehensive determination and
documentation of the basis for approval for that DSA and TSRs or at the discretion of the SBAA.
SERs may be issued and approved with minority opinions, even minority opinions
recommending against approval.
7.2 SER CONTENT AND FORMAT
The SER addresses only those issues that are germane to documenting the basis of acceptance of
the safety basis document being reviewed; therefore, the SER is subject to the graded approach.
Summaries of material already contained in the safety basis document being reviewed should be
brief, but sufficient to provide a knowledgeable reader a basic understanding of the basis of
approving these documents. This Standard principally addresses the preparation of SERs for
DSAs and TSRs that comply with the DOE-STD-3009 safe harbor. There are other potential
safe harbors allowed in 10 CFR Part 830 (such as Regulatory Guide 1.70 or DOE O 460.1C,
Packaging and Transportation Safety). The format of the SER should be based on the safe
harbor methodology used.
Section 30
The depth and complexity of an SER should be commensurate with the significance and
complexity of the safety basis document being reviewed. Aspects of a DSA that represent
unique or novel topics, or where the approach is based on evolving technical issues, whose
evaluation by DOE may be later questioned should be specifically addressed in the SER. A
modified SER format may be used for other safety basis documents (e.g., JCOs) that are
described in Section 6 of this Standard. A simple letter or report may also be adequate
depending on the complexity of the safety basis document being reviewed. In such cases the
letter or report shall address the following:
• The sufficiency of the safety basis document for a hazard category 1, 2, or 3 DOE nuclear
facility;
• The extent to which a contractor has satisfied the requirements of Subpart B of 10 CFR
Part 830; and
• The basis for approval by DOE of the safety basis for the facility, including any
conditions for approval.
The following SER format shall be used on a graded approach consistent with the preceding
discussion.
DOE-STD-1104-2016
31
7.2.1 Title Page
The title page provides the unique identifier information for the safety basis document being
reviewed and the SER. The title page also provides the following information, at a minimum:
• SER title, revision number, and date issued;
• Title, revision number, and date issued for the safety basis document being reviewed;
• Facility name and identification number, if any;
• Site; and
• Optionally, the DOE contractor’s name and appropriate contract number.
7.2.2 Signature Page
The signature page provides the identification and signature of the SBAA, and the approval date
of the safety basis document being reviewed. Other signatures may be provided at the discretion
of the SBAA.
7.2.3 Executive Summary
This section presents summary information regarding the basis for approval of the safety basis
document being reviewed. The introduction contains the following information, which is briefly
summarized: (1) clear identification of the facility for which approval is being granted and its
hazard category; (2) statement of the facility mission and scope of operations encompassed by
the facility mission; (3) summary of the major facility hazards and dominant accident scenarios;
(4) discussion of pertinent exemptions and/or consent agreements impacting the approval;
(5) discussions of major mission and project-related influences affecting the decision to authorize
operation; and (6) any conditions of approval and/or open issues raised with regard to the
approval bases, including associated paths forward for resolution (if applicable). The executive
summary concludes with a statement on the acceptability of the safety basis document(s) being
reviewed, indicating that these documents have undergone an appropriate review.
For an acceptable PDSA, the executive summary states that the PDSA provides a reasonable
basis for the preliminary conclusion that the nuclear facility can be operated safely based on the
following: (1) the nuclear safety design criteria in DOE O 420.1C (or successor document in the
site contract) have been satisfied; (2) a safety analysis meeting DOE O 420.1C and DOE-STD-
1189-2016 requirements to support the design has been performed; and (3) an initial listing is
provided of the safety management programs that have been or will be developed to address
operational safety considerations.
7.2.4 Review Process
Section 31
This section provides a brief description of the review process that the safety basis document has
undergone. Typical information summarized includes the following: (1) basic premises of
review, particularly those representing some consensus with the preparer of the safety basis
document being reviewed; (2) summation of the review effort; (3) key participants in the review
process; and (4) scope of special efforts, if any, such as selected independent calculations or
walkthroughs. Discussion should be sufficient to provide an understanding of the thoroughness
DOE-STD-1104-2016
32
of the review process and its basis. This section does not provide a documented record of the
details of the review (e.g., issue resolution files).
7.2.5 Base Information
This section documents the bases of approving the adequacy of base information, including any
conditions of approval imposed. A statement of adequacy is generally focused and brief. This
may entail nothing more than a paragraph stating that the safety basis document contains
sufficient background and fundamental information to support the review of the more technical
aspects of the documents (i.e., review of the remaining approval bases). The majority of any
inadequacies in the base information will require revision to the DSA or the TSRs prior to SER
preparation, or may be sufficiently minor that they can be resolved in a future revision of the
DSA or TSRs.
In addition to bases of acceptance, this SER section provides a synopsis of major site, facility,
and operational process features. This information provides a facility-specific context for SER
bases of approval such that an elementary understanding of the operational envelope can be
gleaned from the SER. The SER does not, however, attempt to repeat detailed safety basis
information contained in the safety basis document.
7.2.6 Hazard and Accident Analyses
This section documents the bases for approving the hazard and accident analyses, including any
conditions of approval imposed. Such documentation focuses on the completeness of the
analysis and the consistency of the logic used throughout the analysis process.
In addition to bases of acceptance, this SER section provides the following information:
• A synopsis of hazards identified;
• Fundamental aspects of defense-in-depth, worker safety, and environmental protection;
• Dominant accident potentials;
• Accident consequences relative to the EG for safety class controls to protect the public;
• Qualitative and/or semi-quantitative technique estimate of toxicological consequences
relative to safety significant control guidelines for the public; and
• Qualitative and/or semi-quantitative technique estimate of facility and co-located worker
radiological and/or toxicological consequences relative to safety significant control
guidelines.
The purpose of summarizing this information is not to recapture detailed information already
present in the safety basis document. The summary provides the reader with an elementary
understanding of the major facility hazards. In summarizing this information, the SER does not
repeat the details of the safety basis assumptions or calculations. The SER may, however,
discuss essential aspects of important issues resolved during the review process.
DOE-STD-1104-2016
33
7.2.7 Safety Structures, Systems, and Components (SSCs)
Section 32
This section documents the bases for approving the designation of safety SSCs and their
associated safety functions, functional requirements, system evaluations, and potential TSR
coverage, including any conditions of approval imposed. Focus is on the consistency of the logic
developed in hazard and accident analyses being carried through to the identification of safety
SSCs and on the definitions and descriptions provided for these SSCs.
In addition to bases of acceptance, this SER section provides a synopsis of safety SSCs and their
safety functions as determined in the hazard and accident analyses. The purpose of summarizing
this information is not to recapture detailed information already presented in the safety basis
document. The summary provides a reader with an elementary understanding of the safety SSCs
and the bases of their designation in hazard and accident analyses. The SER may, however,
discuss essential aspects of important issues resolved during the review process.
7.2.8 Specific Administrative Controls
This section documents the bases for approving the SACs, as well as their associated safety
functions, functional requirements, system evaluations, and potential TSR coverage, including
any conditions of approval imposed. The basis for acceptance of SACs is similar to that for
safety SSCs, except that the discussion in the safety analysis for SACs should justify the use of
SACs over engineered safety features. It is not expected that SACs will be developed in detail at
final design (for the PDSA). The safety function of SACs is clearly defined so that the decision
to use an SAC rather than a safety SSC can be evaluated. Expectations regarding SACs are
defined in DOE-STD-1186-2016 (or other approved document) and expectations for the
discussion of SACs in the PDSA are discussed in Appendix D of DOE-STD-1189-2016.
7.2.9 Derivation of Technical Safety Requirements
This section documents the bases for approving the derivation of TSRs, including any conditions
of approval imposed. Such documentation focuses on the consistency of the logic developed in
the DSA hazard and accident analyses, and the DSA description of SSCs and SACs being carried
through to the derivation of TSRs. The TSRs required by 10 CFR § 830.205 are not specified in
a DSA, which is only required to provide the basis of their derivation.
In addition to bases of acceptance, the SER section provides a synopsis of the derivation of TSRs
as a function of the hazard and accident analyses. This information is intended for the sole
purpose of providing minimal, facility-specific context for SER bases of approval, such that an
elementary understanding of the operational envelope can be gleaned from the SER. The SER
does not, however, repeat detailed information contained in the DSA.
DOE-STD-1104-2016
34
7.2.10 Safety Management Programs
This section documents the bases of approving safety management programs, including any
conditions of approval imposed. These bases relate to identification of the basic capability and
awareness of fundamental provisions and performance expectations needed for maintaining the
adequacy of the facility safety basis. This approval documents that the basic elements of the
institutional safety management programs depended on for ensuring facility safety basis are
adequate and that these elements can and will be implemented. It is sufficient to provide a
program list which notes basic program principles and relationship to defense-in-depth, worker
safety, and/or dominant accident scenarios.
Section 33
The PDSA may provide little or no detail provided for the safety management programs, because
these programs will not have been developed at the time the PDSA is written. Consequently, this
section of the SER for the PDSA may be limited to affirming the need for such programs in the
DSA.
7.2.11 Technical Safety Requirements
This section documents the basis of approving the TSRs, including verification that the
commitments for safety controls that are made in the DSA are carried through to TSR provisions.
The technical bases for selection of specific types of controls should be documented as part of
the review and summarized in this section of the SER. DOE G 423.1-1B (or successor document
per site contract) may be used to establish review criteria for TSRs.
The SER for the PDSA should address the review of the bases for TSRs in the PDSA consistent
with the hazard and accident analyses, as well as a summary table for the TSRs. The TSR safety
limits, limiting control settings, LCO, surveillance requirements, administrative controls, and
design features should be listed in the PDSA consistent with the hazard and accident analyses.
7.2.12 Conditions of Approval
Conditions of approval should be written such that the conditions required to be met and the
actions required to be implemented are clearly articulated. Durations, implementation periods,
and/or completion dates should also be specified so that it is clear when compliance with the
condition of approval is expected to occur. The reason, referencing the applicable DOE
directives and regulations, for including any conditions of approval should be clearly stated in
the SER, as well as the basis for the conclusion that continued operation under the condition of
approval is acceptable and consistent with adequate protection of workers and the public.
Whenever a compensatory measure is needed to ensure appropriate safety levels are maintained
while a temporary condition of approval is in effect, that compensatory measure shall be clearly
articulated in the SER. It then becomes part of the facility safety basis.
For SERs that address existing facilities with accident consequences over the EG, see Section 4.9
of this Standard for additional requirements.
DOE-STD-1104-2016
35
7.2.13 Records
This section provides references to the essential records, documentation, and information
generated throughout the review process. These references may include the following: (1) the
review plan and schedule; (2) minutes of review meetings, including meetings with the facility
contractor; (3) dates and the results of facility walkthroughs; (4) submittal of issues and their
disposition; (5) documentation generated in resolution of issues; and (6) documentation
regarding commitments made by the facility contractor for approval of the safety basis
document. References should be complete and accurate enough to locate necessary information
during future revision and review activities if needed.
References that have been reviewed may be listed in the appropriate approval basis sections.
Records of “in-process review” comments if applicable per the review plan are not required to be
retained.
7.3 SAFETY BASIS INFORMATION SYSTEM DATABASE
Section 34
10 CFR Part 830 Subpart B, Appendix A, I.2. states “DOE will maintain a public list on the
internet that provides the status of the safety basis for each hazard category 1, 2, and 3 DOE
nuclear facility…” DOE O 231.1B, Environment, Safety and Health Reporting, reiterates this
requirement and assigns responsibility to the Field Element Manager. The DOE safety basis
approval authority should provide up-to-date information to the Safety Basis Information System
Database, unless the Field Element Manager designates another responsible party.
DOE-STD-1104-2016
36
8.0 SAFETY DESIGN BASIS DOCUMENTS
The purpose of safety design basis documents is to ensure that an acceptable approach to nuclear
safety is effectively integrated into the design as early as possible. Timely and effective
integration of safety into design helps prevent significant impacts on project cost and schedule
due to changes in design or construction at a later date when such changes have a greater project
impact. Significant project impacts can also have safety impacts by deferring risk remediation,
for example. The interactive process between safety analysis and design should begin as early as
possible so that safety is effectively integrated into the design process.
In particular, this Section provides expectations for the review of the SDS, long-lead
procurement SSCs, CSDR, Preliminary Safety and Design Results, and the PDSA. These
documents (referred to in this Standard as safety design basis documents) are progressive
documents for the design phases of a project that lead to the development of the DSA and the
TSR. Approval of each phase of the design establishes the readiness to proceed to the next
phase. Review and approval of these documents during the design phases ensure communication
between DOE and its contractors regarding facility design, as well as ensuring that safety-in-
design is incorporated early in the design process.
DOE review and approval of safety design basis documents shall ensure that design basis
accidents (DBAs) identified for new facilities and major modifications are prevented or have
mitigated offsite dose consequences below the EG.
The relationship of safety design basis documents and the order of their development are
summarized as follows:
• The SDS provides a roadmap for strategizing how important safety issues will be
addressed in the design and in the tailoring of the development of key safety
documentation.
• The CSDR summarizes the hazards analysis efforts and key safety-in-design decisions
incorporated into the conceptual design, along with any identified project risks associated
with the selected strategies.
• Long-lead procurement items that may be identified and require DOE review and
approval on an expedited basis.
• The Preliminary Safety and Design Results update and add design detail to the
information in the CSDR.
• The PDSA demonstrates the adequacy of the design from the safety prospective to
support construction of the facility.
• The DSA evolves from the PDSA and reflects the as-built design.
• The TSRs are developed, based upon the DSA.
DOE-STD-1104-2016
37
The level of detail for the review of safety design basis documents may be graded based on the
scope and complexity of the facility/change and the hazards and risks involved. Familiarity with
DOE-STD-1189-2016 is essential to proper application of this Section.
Section 35
When required by DOE O 420.1C, the DOE-STD-1189-2016 process applies to facility changes
determined to be major modifications, as defined by 10 CFR 830, Subpart B. DOE-STD-1189-
2016 provides a process and guidance for making determinations about whether a facility change
constitutes a major modification. DOE-STD-1189-2016, Section 5.2, requires contractors to
provide major modification assessments assigned at least one “yes” answer to the DOE Field
Element Manager or designee, together with supporting technical justification. The SBAA or
designee shall review such major modification assessments and provide the contractor feedback
if the SBAA disagrees with the determination.
In cases where a project is following DOE-STD-1189-2008, the Sections below (8.1-8.7) may be
tailored for the review and approval of the safety design basis documents.
8.1 SAFETY BASIS REVIEW TEAM
The SBRT concept is introduced in Section 3. This Section expands on that description for use
of an SBRT in reviewing safety design basis documents. DOE O 413.3B (or successor
document) defines the roles and responsibilities for DOE in managing a project, including who
assigns the responsibility for reviewing and approving safety design basis documents submitted
to DOE. The SDS, CSDR, the Preliminary Safety and Design Results, the PDSA, the DSA, and
the TSRs are approved by the SBAA.
The SBAA should establish a SBRT and appoint a senior staff person qualified under the DOE
Technical Qualifications Program to lead the SBRT for those documents that require DOE
approval (see Section 3 for discussion of the SBRT). The SBRT is expected to:
• Review the SDS and prepare the safety review letter for the SDS;
• Review the CSDR and prepare the safety review letter for the CSDR;
• Review the Preliminary Safety and Design Results and prepare the safety review letter
for the Preliminary Safety and Design Results; and
• Review the PDSA and prepare the SER for the PDSA.
At each step, the SBRT should ensure that previously identified issues have been adequately
addressed. The SBRT lead should maintain communication with the Federal Integrated Project
Team and the Safety Design Integration Team (SDIT)5 as the design progresses to ensure that
the Integrated Project Team is kept up to date with respect to safety design. The SBRT should
attend design review meetings and review and comment on the SDS; however, it should be
careful to remain independent of the development of the CSDR, Preliminary Safety and Design
Results, and PDSA to ensure independence in the review of those documents. Maintaining this
5 See DOE O 413.3B, and DOE-STD-1189-2016 or successor documents for requirements and additional
information on the Integrated Project Team and Safety Design Integration Team.
DOE-STD-1104-2016
38
independence does not prohibit the SBRT from participating in “in-process reviews” of draft
safety design basis documents or their supporting hazard analysis, accident analysis, and control
selections as they are being developed and reviewed by the SDIT and other project staff. The
review plan developed by the SBRT should identify whether the SBRT will be included in
“in-process reviews” and expectations, e.g., comments may be informally provided to the
document preparers via the SBRT leader without the requirement for comment closure to
encourage early identification and resolutions of issues. “In-process reviews” are a good practice
when projects are significant and the SBRT can be adequately staffed to support “in process
reviews.” In process reviews are more likely to result in timely DOE review and feedback, and
more likely to support meeting project baselines.
Section 36
As discussed above, the safety design basis documents are progressive documents drawing from
the analyses and information in the previous document and evolving with the design of the
facility. Consequently, the SBRT should be staffed with members who can stay with the review
process as it progresses. Having long-term team members adds efficiency to the team effort as
they carry the history of the safety design bases documents with them. Over time, some team
members may change due to attrition, promotions, the need to add individuals to the review team
to include specific technical skills, or the decision to drop certain individuals whose skills are no
longer needed. However, the continuity of the SBRT team leader is essential; therefore, that
individual should be chosen with this in mind.
The conceptual design phase of a project presents a key opportunity for the safety analysis to
influence the design. Because important preliminary analyses and safety design decisions are
taken during this period, the SBRT should be actively involved in the review process. The
SBRT lead should identify and assign Subject Matter Experts in the review of
safety-in-design issues as they are identified. These Subject Matter Experts should become
members of the SBRT. The team lead should make use of all available resources. For example,
review of the project (or other projects) conducted by the Defense Nuclear Facilities Safety
Board (DNFSB) may identify design issues that should be addressed early in the design process.
The review plan should address whether or not a phased approach will be used in reviewing
Preliminary Safety and Design Results. Review of Preliminary Safety and Design Results
should occur as soon as these results are available, on a schedule that can effectively influence
final design. A phased approach to release and review of Preliminary Safety and Design Results
can be the most effective approach for obtaining timely DOE feedback on these results,
minimizing project impacts. The definition of the phases should be carefully considered for
interdependencies of major systems. The SBRT, in conjunction with the Federal Project
Director, should coordinate with the SDIT to define any DOE reviews in the SDS, such as when
multiple reviews are used for review of Preliminary Safety and Design Results.
8.2 REVIEW BASES FOR SAFETY DESIGN STRATEGY
DOE expectations for safety-in-design developed during the pre-conceptual phase evolve into
the SDS during the conceptual phase. The SDS provides the preliminary information to gauge
the scope of significant hazards and the general strategy for addressing those hazards. In
addition, for projects that do not follow the traditional project cycle, the SDS provides a vehicle
to describe how requirements for safety documentation will be tailored to that particular project
DOE-STD-1104-2016
39
approach, while at the same time satisfying the requirements of DOE O 413.3B (or successor
document). DOE-STD-1189-2016 is based on the assumption that the safety basis for the
facility being constructed or modified will be based on the format and content of
DOE-STD-3009-2014. If applicable, and if approved, a different format and/or content may be
used.
The SDS, at the conceptual design phase, is prepared by the SDIT (or the contractor safety lead
in the absence of an SDIT) from the DOE expectations for the execution of safety activities
during design.
Section 37
When a new project enters the conceptual design phase, Section 3.3 of DOE-STD-1189-2016
calls for the development of an SDS as one of the first safety documents to be generated. The
requirements and expectations for the SDS are defined in Section 3.3 and Appendix B of DOE-
STD-1189-2016, respectively. The SDS is approved by SBAA and the Federal Project Director,
with the concurrence of the Chief of Nuclear Safety or advice from the Chief of Defense Nuclear
Safety, as appropriate. DOE O 413.3B, assigns to the PSO the authority to designate the SBAA
for the project. DOE shall document the review of the SDS in a safety review letter for approval
by the SBAA and the Federal Project Director, with the concurrence of the Chief of Nuclear
Safety or advice from the Chief of Defense Nuclear Safety, as appropriate.
The SDS is updated in the preliminary and final design phases, or as necessary to reflect
significant changes in the design or safety strategy. Updates to the SDS should focus on the
major safety decisions that influence project cost or schedule. Such decisions may involve
seismic design criteria, confinement ventilation, safety functional classification, long-lead items,
and safety and design strategies. Interim SDS updates provide a means by which all parties are
kept informed of important changes due to safety-in-design evolution between Critical Decision
(CD) points. DOE shall review and approve updates of the SDS.
The SDS lays out the strategy for the safety design of the project, and defines the framework and
review schedule of a number of the project safety documents to be approved by DOE, including
the CSDR, the Preliminary Safety and Design Results, the PDSA, the DSA, and the TSRs. The
SDS review should evaluate whether the requirements of DOE-STD-1189-2016, Section 3.3, and
the topics described in DOE-STD-1189-2016, Appendix B, have been addressed and provide an
adequate basis to proceed with design efforts. In particular, the SDS review should ensure that
the SDS contains a clear description of the Preliminary Safety and Design Results, and adequate
hold points are established between preliminary design and final design.
Review of the SDS includes review of the strategy for structuring and managing the project
design organization and its support contractors. Organizational staffing, structuring, and
processes have often proven to be a vital factor in overall project success including successful
and timely integration of safety into design. For example, if design and safety analysis personnel
are not co-located, a strong liaison function should be provided. Adequate input to design teams
from persons with operational experience is important to developing designs that can be
effectively operated and maintained.
DOE-STD-1104-2016
40
8.3 REVIEW BASES FOR CONCEPTUAL SAFETY DESIGN REPORTS
DOE O 413.3B, requires a CSDR as a part of the approval package for the CD-1 phase of a
project. The purpose of the CSDR is to summarize the hazards analysis efforts and safety-in-
design decisions incorporated into the conceptual design along with any identified project risks
associated with the selected strategies. The purpose of the approved CSDR is to ensure that the
decisions made regarding project safety are explicitly identified and dealt with in early stages of
the design.
Section 38
DOE-STD-1189-2016 provides details on DOE’s expectations for the CSDR. In particular,
Appendix H of that standard provides a format and content guide for the CSDR. DOE-STD-
1189-2016 is based on the assumption that the safety basis for the facility being constructed or
modified will be based on the format and content of DOE-STD-3009-2014. If applicable, and if
approved, a different format and/or content may be used. The format and content of the CSDR
should be tailored to the maturity of the design and safety analysis at the conceptual design
phase. As described in DOE-STD-1189-2016, the CSDR reflects the project configuration at
conceptual design; however, the design at this phase is not fully defined and so the CSDR can
potentially propose more than one possible approach to some aspects of the design, and identify
areas needing further research and development at later stages. Consequently, a comprehensive
safety assessment at the conceptual design stage is not feasible.
Although some of the decisions and selections may be preliminary at this phase of design, the
SBAA or designee shall confirm that the following are adequate and sufficiently conservative to
support proceeding from the conceptual design phase to the preliminary design phase:
• Initial hazard categorization of the facility (hazard category-1, -2 or -3);
• Preliminary identification and analysis of the facility hazards and DBAs;
• An assessment, based on significant hazard scenarios and DBAs, of the need for safety
class and safety significant hazards controls;
• Consideration of inherently safer design concepts, and application of the hierarchy of
controls;
• Preliminary assessment of the applicable natural phenomena hazards (NPH) design
criteria; and
• Approach to meeting the safety design criteria of DOE O 420.1C, or approved
exemptions and equivalencies.
The reviewer should refer to DOE-STD-1189-2016, Appendix C, for detailed guidelines on the
expected contents for a CSDR. These contents may vary somewhat based on the individual
project, as documented in the SDS. As part of the review of the CSDR, the SBAA or designee
shall perform the following review activities:
• Assess whether the selected alternative is acceptable for safety-in-design integration;
DOE-STD-1104-2016
41
• Assess whether the identified facility level DBAs appear to be a complete and bounding
set;
• Assess the adequacy of the hazard analysis against the expectations in Section 4.3.1 and
4.3.2 of DOE-STD-1189-2016;
• Evaluate whether the safety classification of the safety controls and associated safety
functions identified are appropriate and consistent with Sections 4.3.3 and 4.3.4 of
DOE-STD-1189-2016;
• Evaluate the technical adequacy of the basis of the chosen confinement strategy (i.e.,
active confinement ventilation is preferred over passive confinement systems per DOE O
420.1C, which states that “Alternate confinement approaches may be acceptable if a
technical evaluation demonstrates that the alternate confinement approach results in very
high assurance of the confinement of radioactive materials” and includes a footnote
stating that “The safety classification (if any) of the ventilation system is determined by
the facility documented safety analysis.”);
• Confirm that the current safety design basis is conservative and the risk of significant
redesign related to major or costly changes in safety controls is minimized or identified in
the CSDR;
Section 39
• Confirm that the CSDR or Risk and Opportunity Assessment contains a summary of the
risks and opportunities6 associated with the safety design basis strategies and adequate
risk handling strategies that bound each identified risk;
• Evaluate whether defense in depth is adequately implemented consistent with Section 4.1
of DOE-STD-1189-2016;
• Ensure that any open conditions of approval from the DOE review of the SDS are
resolved;
• Confirm that major SSCs achieve TRL-4 (See DOE G 413.3-4A, Technology Readiness
Assessment Guide, for additional information);
• Ensure that any safety issues that require further study, including TRL activities, are
identified in the CSDR;
• Confirm that the safety design aspects of the project support moving ahead to the
preliminary design phase and all DBAs considered for new facilities have been prevented
or have mitigated offsite dose consequences below the EG; and,
• Evaluate the CSDR to ensure that the hazard controls were selected consistent with the
principles of the hierarchy of hazard controls.7
6 See DOE-STD-1189-2016, Appendix C, for information on expectation for the risk and opportunity assessment.
7 See Section 4.1.4 in DOE-STD-1189-2016.
DOE-STD-1104-2016
42
The SBAA or designee shall document the results of the review of the CSDR in a safety review
letter. The Federal Project Director concurs on the safety review letter for the CSDR. Guidance
for the preparation of an CSDR safety review letter is provided in Section 8.7.
8.4 REVIEW OF LONG-LEAD PROCUREMENT SSCs
Long-lead procurement items that are identified in accordance with DOE-STD-1189-2016,
Section 4.5.3, require DOE review and approval on an expedited basis. For long-lead
procurement items that are identified as non-safety SSCs, the SBAA or designee shall confirm
that the SSCs are non-safety and do not impact safety functions. For long-lead procurement
items that are identified as safety SSCs, the SBAA or designee shall review the adequacy of the
required safety documentation. The SBAA shall document approval of long-lead procurement
items in a safety review letter.
8.5 REVIEW BASES FOR PRELIMINARY SAFETY AND DESIGN RESULTS
The Preliminary Safety and Design Results evolve from and expand upon the CSDR adding
design detail from the preliminary design phase of a project. Review and approval of the
Preliminary Safety and Design Results occurs in between CD-1 and CD-2, and should be
scheduled as early as practicable, to minimize project risk. DOE-STD-1189-2016 provides
details on DOE’s expectations for the Preliminary Safety and Design Results. Note: The review
expectations identified in this section may be met in coordination with other reviews (e.g.,
Design Reviews, Technology Readiness Assessments, Technical Independent Peer Reviews,
etc.). It is the responsibility of the approval authority (the SBAA, unless otherwise designated by
the PSO) to demonstrate that the review requirements of this Section have been satisfied.
The SBAA or designee shall determine whether the Preliminary Safety and Design Results
adequately address the following safety design basis aspects for the preliminary design phase:
• Completeness of the Preliminary Safety and Design Results, and consistency of design
with the safety strategy provided in the SDS;
• Resolution of any open conditions of approval identified in the safety review letter for the
CSDR;
Section 40
• Approach to meeting the general design criteria of DOE O 420.1C, Chg. 1, Attachment 3
(or approved exemptions and equivalencies), and identification of appropriate codes and
standards, including technical justifications, as necessary;
• Identification and description of a viable design solution (in terms of major safety SSCs)
that provides the safety functions called for in the hazard and accident analysis;
o The unmitigated accident consequence assessment provides adequate basis to assign
appropriate functional classification and NPH design categories for major SSCs, and
o The hazard and accident analysis provides adequate basis to identify the functional
requirements and conditions that the major safety SSCs need to address.
DOE-STD-1104-2016
43
• Consideration of inherently safer design concepts, and application of the hierarchy of
controls;
• Identification and description of the technical studies needed to complete the safety
design, including TRL activities; and
• Identification and description of safety design risks and risk mitigation strategies for the
final design phase.
As described in DOE-STD-1189-2016, the Preliminary Safety and Design Results are intended
to demonstrate the adequacy of the hazard and accident analyses and the selection and
classification of the safety controls, including consideration of the application of the principles
associated with the hierarchy of controls. The information in the Preliminary Safety and Design
Results should be sufficient to conclude, that if the commitments made in the Preliminary Safety
and Design Results and design documents are met, the result should be a final design and a
constructed facility that could be approved for operation without significant modifications. The
detail in the Preliminary Safety and Design Results will be more complete than the information
provided in the CSDR, even though the design may not be complete.
It is not necessary that the full details of consensus design codes and standards be listed in the
Preliminary Safety and Design Results. These details should be in the documents available for
the design reviews and should be fully scrutinized during design reviews by safety personnel
participating in those reviews.
Reviewers should refer to DOE-STD-1189-2016, for detailed guidelines on the expected
Preliminary Safety and Design Results. The review may consist of a single review or a series of
reviews, based on when the preliminary design of the facility (or of defined segments of the
design) is complete and ready to enter final design. These contents may vary somewhat based on
the individual project, as documented in the SDS. As part of the review of the Preliminary
Safety and Design Results, the SBAA or designee shall perform the following review activities:
• Review the adequacy and completeness of the set of codes, standards, and requirements
identified in the Code of Record and, on a sampling basis, evaluate whether its
requirements have been addressed by the preliminary design;
• Assess the adequacy of the hazard and accident analysis against the expectations in
Section 4.4 of DOE-STD-1189-2016;
• Confirm that the hazard and accident analysis is complete to the degree appropriate for
the stage of development;
• Review whether the FHA is adequate for this stage of development;
• Confirm that all DBAs considered for new facilities have been prevented or have
mitigated offsite dose consequences below the EG;
Section 41
• Confirm that the current safety design basis is conservative and the risk of significant
DOE-STD-1104-2016
44
redesign related to major or costly changes in safety controls is minimized or clearly
identified;
• Confirm that major safety SSCs and SACs, if necessary, are identified and described,
including safety function, relationship to hazard and accident analysis, functional
requirements, and performance criteria judged to require TSRs;
• Review adequacy of identification of any safety SSCs that are intended to become design
features for implementing TSRs;
• Evaluate the decisions made with respect to the functional classification and NPH design
category of the safety controls, and adequate implementation of defense-in-depth;
• Review whether a viable design solution (in terms of major safety SSCs) has been
identified and described to provide the safety functions called for in the hazard and
accident analysis;
• Review the risk and opportunity assessment to confirm that technical uncertainties related
to safety are adequately identified and addressed;
• Confirm technology readiness of major SSCs is sufficient (See G 413.3-4A for additional
information); and
• Confirm that significant uncertainties do not exist, or are identified with appropriate risk
mitigation strategies, such that detailed design can proceed.
The SBAA, with the support of the SBRT, shall document the review and approval of the
Preliminary Safety and Design Results in a safety review letter. The Federal Project Director
concurs on this safety review letter. Guidance for the preparation of a safety review letter for the
Preliminary Safety and Design Results are provided in Section 8.7 of this Standard.
In cases where a project is following DOE-STD-1189-2008 for development of a Preliminary
Safety Design Report, this Section should be tailored for the review and approval of the
Preliminary Safety Design Report.
8.6 APPROVAL BASES FOR PRELIMINARY DOCUMENTED SAFETY
ANALYSES
Title 10 CFR § 830.206 requires a PDSA for new facilities and major modifications initiated
after December 11, 2000. Section 830.3 of the rule defines the PDSA as follows:
Preliminary documented safety analysis means documentation prepared in
connection with the design and construction of a new DOE nuclear facility or a
major modification to a DOE nuclear facility that provides a reasonable basis for
the preliminary conclusion that the nuclear facility can be operated safely through
the consideration of factors such as:
(1) The nuclear safety design criteria to be satisfied;
DOE-STD-1104-2016
45
(2) A safety analysis that derives aspects of design that are necessary to
satisfy the nuclear safety design criteria; and
(3) An initial listing of the safety management programs [to] be developed to
address operational safety considerations.
The PDSA is, in part, to ensure that DOE and the contractor agree that safety has been
adequately integrated into the design before construction begins. Title 10 CFR § 830.206
requires that DOE approve the nuclear safety design criteria used to prepare the PDSA unless the
contractor uses the design criteria in DOE O 420.1C. The PDSA is revised as needed to reflect
design changes (see DOE-STD-1189-2016, Section 3.8.3 for more information on changes that
would necessitate a PDSA revision). When a PDSA is required, it shall be approved by DOE
before the contractor can procure materials or components or begin construction, unless DOE
provides relief under the provisions of the Rule.8
Section 42
The PDSA evolves from the Preliminary Safety and Design Results and follows the format and
content expectations as defined in Appendix D of DOE-STD-1189-2016. The format and
content expectations are tailored to the design and safety analysis maturity at the final design
stage.
As described in DOE-STD-1189-2016, the PDSA and SDS are required to identify any changes
that were made to the decisions and commitments in the Preliminary Safety and Design Results.
Furthermore, while the CSDR should include a facility-level hazards analysis and the
Preliminary Safety and Design Results should include a process-level hazards analysis, the
PDSA is expected to address activity-level hazards and hazard controls and evaluate
facility/process hazards. This should be confirmed during the review of the PDSA.
The PDSA is typically submitted for approval during the Final Design Phase of a project. The
review of the PDSA shall confirm that:
• The design safety analysis is complete and demonstrates the adequacy of the design from
the safety perspective. The PDSA does not need to show the progression of the design
that led to the final choices, only the final choices and the justification for their adequacy;
• The safety design requirements specified at the end of the preliminary design have been
met;
• The hazards and accident analysis is consistent with DOE-STD-1189-2016, Section 4.5;
• The DBAs considered for new facilities have been prevented or have mitigated offsite
dose consequences below the EG;
8 10 CFR Part 830 states, “DOE may authorize the contractor to perform limited procurement and construction
activities without approval of the PDSA if DOE determines that the activities are not detrimental to public health
and safety and are in the best interests of DOE.” Where applicable, such authorizations should be documented, with
rationale, and communicated to the contractor.
DOE-STD-1104-2016
46
• The description of the final design of the facility is adequate with respect to safety SSCs
and safety design features;
• Safety SSCs, SACs, and other hazard controls are identified and their performance
requirements are clearly stated. In addition to the review consideration presented in
Section 8.5 of this Standard regarding SACs, expectations for the discussion of SACs in
the PDSA are included in Appendix D of DOE-STD-1189-2016;
• The description of how the selected safety controls prevent and/or mitigate identified
hazards and accidents is adequate;
• The description of how selected safety controls provide defense-in-depth is adequate,
based on mitigated accident frequency and on control reliability;9
• The initial list of safety management programs is complete;
• The description of how the nuclear safety design criteria of DOE O 420.1C (or applicable
version) have been satisfied by the design is adequate;
• Confirm that major SSCs achieve TRL-7 (See DOE G 413.3-4A for additional
information);
• Any technical issues that required research or other data collection to finalize the design
have been resolved;10
• Preliminary approaches to startup and operations management have been documented;
and
• Any open conditions of approval identified in the safety review letter for the Preliminary
Safety and Design Results have been resolved.
Section 4 of this Standard provides an extensive listing of bases of approval for DSAs. Many of
these are applicable and should be used in review of PDSAs. In particular, Section 4.3 through
Section 4.6 provide important bases of approval for hazards and accident analysis, and selection
of safety controls.
Section 43
If the PDSA’s format and content differ from those defined in Appendix D of DOE-STD-1189-
9 This analysis should provide adequate understanding of the baseline mitigated consequences for the facility. The
description should define the safety control effectiveness in the context of the potential accidents and provide the
baseline safety analysis for the evaluation of changes as the facility DSA is developed for the transition to
operation.
10 The technical issue(s) giving rise to the need for research or other data collection should be identified in the
project Risk and Opportunity Assessment, including the plan and rationale for resolution of the issue(s). See
DOE-STD-1189-2016, Section 4.1.6, and Appendix C. DOE reviewers should evaluate the risk and opportunity
evaluation to ensure that it is robust in identifying unknowns and potential technical issues related to the results of
the hazard analysis; specifically, the selection of hazard controls.
DOE-STD-1104-2016
47
2016, the reviewer should verify that the PDSA follows the expectations defined in the SDS.
The expectations for integration of safety-in-design criteria defined in DOE-STD-1189-2016 still
apply. In any event, the PDSA should be developed to support the development of a DSA that
complies with the requirements of 10 CFR Part 830 to avoid problems during the review of the
DSA. In some cases, PDSAs developed in accordance with DOE-STD-1189-2016 will contain
more information than that required to support DSA safe harbor methods in Appendix A to
Subpart B of 10 CFR Part 830.
Prior to operations, the PDSA will evolve to a final DSA that reflects the facility as actually
constructed. DOE does not expect PDSAs for activities that do not involve significant
construction, such as environmental restoration activities, decontamination and decommissioning
activities, specific nuclear explosives operations, or transition surveillance and maintenance
activities.
The SBAA or designee shall document the review of the PDSA in an SER. The format and
content expectations of the SER are provided in Section 7 of this Standard. DOE reviewers for
PDSAs should be mindful that the PDSA is based on the available knowledge of equipment to be
procured after the PDSA is approved, particularly if approval of long-lead items is requested to
facilitate early construction and procurement. Therefore, it is recommended that the SBAA or
designee for the PDSA prepare the SER for the review and approval of the PDSA based on one
of the following findings/evaluations:
• Proposed design item/system/activity has been completely reviewed and found
acceptable (subject to any DOE-imposed changes), or
• Proposed design item/system/activity is based on preliminary information and is
conditionally accepted based on commitments to fully meet specific safety criteria in the
final DSA (e.g., separation, redundancy, maintainability access).
While it is most desirable for the reviewers to be able to make the first finding listed above, the
design may not be sufficiently mature to reach that conclusion. Consequently, if the second
finding is chosen, DOE should direct the contractor to revise and re-submit the PDSA for
approval consistent with the changes made to the design as it progresses, until such time as it is
superseded by a final DSA. In either case, significant changes to the design after PDSA approval
may require that the PDSA be revised and resubmitted for approval, in accordance with
DOE-STD-1189-2016, Section 3.8.3.
Section 44
In accordance with DOE O 413.3B, approval of the PDSA is a prerequisite to CD-3; therefore
the Federal Project Director concurs on the SER for the PDSA. Detailed expectations for the
preparation of an SER for the PDSA are provided in Section 7 of this Standard.
8.7 SAFETY REVIEW LETTERS
The safety review letter format below may be used to document the review of the safety design
basis document submittal; namely, the SDS, CSDR, long-lead procurement, and the Preliminary
Safety and Design Results. As with SERs, safety review letters should be concise summary
statements of the bases for review of the safety design basis document and any recommended
DOE-STD-1104-2016
48
actions. Some information documented in the safety review letter, such as descriptions of the
site and mission, may be used later in the SERs used to document the reviews of the PDSA,
DSA, and TSRs. However, the information provided in the early safety design basis documents
reviewed is by definition more preliminary than the later safety basis documents.
The main purpose of the review of these early documents is to identify and raise any concerns
with the design early in the process when changes are less expensive to make and to ensure that
the safety design is sufficient to proceed to the next phase of design. Ideally, the safety review
letter will confirm that DOE agrees with the design concepts at these early phases.
If it is a… Then document the
evaluation in a…
SDS
Safety Review Letter
Long-lead Procurement
CSDR
Preliminary Safety and
Design Results
The depth and complexity of a safety review letter should be commensurate with the significance
and complexity of the safety design basis document being reviewed.
The following sections provide guidance on the format and content for the safety review letter in
reviewing safety design basis documents. The format and content may be tailored consistent
with the safety design basis document being reviewed (e.g., review of an SDS as per guidance in
Appendix B of DOE-STD-1189-2016 or review of long-lead procurement items as per Section
4.5.3 of DOE-STD-1189-2016).
The title for the safety review letter provides the unique identifier information for the safety
design basis document, as applicable. Minimum information consists of the following:
• Safety review letter title, revision number, and date issued;
• Title, revision number, and date issued for the safety design basis document as
applicable;
• Facility name and identification number, if any;
• Site; and
• Optionally, name of the prime contractor for the facility and the contract number.
The safety review letter provides the identification and signature of the SBAA and the date of the
approval. Other signatures, such as the Federal Project Director or SBRT lead, may be included
on this page.
DOE-STD-1104-2016
49
8.7.1 Executive Summary
This section presents summary information regarding the basis of the review of the safety design
basis document. The introduction summarizes the following:
• Facility for which review is being conducted;
• Facility hazard category;
• NPH design criteria;
• Facility mission and scope of operations;
• Issues affecting the ability for the project to proceed;
• Conditions of approval for proceeding to the next stage of design;
• Open issues;
• Significant risks or opportunities identified in the document reviewed; and
• Significant outstanding studies or reviews identified in the document reviewed and the
expected schedules.
Section 45
The Executive Summary concludes with a statement on the acceptability of the safety design
basis document, indicating that the document has undergone an appropriate review and the
design information is sufficient to continue the design process. If the design information is not
sufficient, alternate conclusions may be reached, such as (a) the design information is sufficient
to proceed, but with specified conditions; or (b) the project should not proceed to the next phase
until specified actions are completed.
8.7.2 Review Process
This section should provide a brief description of the process used and the rationale for the level
of effort and detail. The description normally includes:
• Key participants in the review process;
• How the review was done (e.g., verification of information, independent calculations,
reading the report and comparing it to other documentation); and
• Scope of the review (e.g., selected independent calculations and design reviews
attended).
Discussion should be sufficient to provide an understanding of the thoroughness of the review
process and its basis. This section does not provide a documented record of the details of the
review (e.g., issue resolution files).
DOE-STD-1104-2016
50
8.7.3 Recommendation to Proceed
This section documents the bases for review and the recommendations to proceed with the
design and construction. The statement on the adequacy is generally focused and brief. This
may entail nothing more than a paragraph stating that the safety design basis document contains
sufficient background and fundamental information to support the progress of the design effort
and contains no open issues or design flaws that would warrant holding or reversing the design
progress. This does not mean that there are no inadequacies as the design is still immature, but
rather that the reviewer believes these inadequacies will be resolved in the normal design process
and the resolutions documented in the next design document (Preliminary Safety and Design
Results for the preliminary design phase and PDSA for the final design phase). If they are
significant, the inadequacies should be documented in the safety review letter for the follow-up
in later reviews, including methods and schedules for resolving them as soon as practicable.
8.7.4 Site and Facility Information
This safety review letter section provides a synopsis of major site, facility, and operational
process features. This information is intended to provide a facility-specific context for the safety
review letter, such that an elementary understanding of the consideration of safety in the design
process can be attained. The safety review letter does not, however, repeat detailed information
contained in the SDS, CSDR, or Preliminary Safety and Design Results. This information may
be used later to support the basis section of the SER for the PDSA or later documents. This
section of the safety review letter is not essential and can be omitted if it is not needed to support
the document.
8.7.5 Hazard Analysis
For the Conceptual Design Phase, this section documents how the hazard and accident analyses
are (a) consistent with DOE-STD-1189-2016, Section 4.3, and (b) follow the format of Appendix
C of that standard, or the format defined and approved in the SDS.
For the Preliminary Design Phase, this section documents how the hazard and accident analyses
are (a) consistent with DOE-STD-1189-2016, Section 4.4 and (b) follow the format defined and
approved in the SDS.
Section 46
8.7.6 Hazard Categorization
This section identifies the designated nuclear facility hazard category level (hazard category 1, 2
or 3) and assess whether the designated level is appropriate. This section addresses any issues
related to any uncertainties in the nuclear facility hazard category level and the potential costs
and opportunities if the level is revised at a later date.
DOE-STD-1104-2016
51
8.7.7 Safety Structures, Systems, and Components
This section addresses the safety SSCs, their bases and their functions, and any issues related to
the identified set.
8.7.8 Specific Administrative Controls
This section addresses any identified SACs, their bases and their functions, and any issues
related to the identified set. It is not expected that the SACs will be developed in detail for the
Preliminary Safety and Design Results and they may not be identified at all for the CSDR.
8.7.9 Other Hazard Controls
This section addresses any issues associated with other hazard controls identified.
8.7.10 Design Codes and Standards
This section provides the basis for approval of the design codes and standards identified in the
CSDR or Preliminary Safety and Design Results, and identify any exceptions to the design codes
and standards listed in DOE O 420.1C and DOE G 420.1-1A, Nonreactor Nuclear Safety Design
Guide for use with DOE O 420.1C, Facility Safety. This section does not constitute an
exemption to the requirements of DOE O 420.1C, which are required to be requested separately
if needed.
8.7.11 Safety Design Criteria
This section assesses any crosswalk in the CSDR or Preliminary Safety and Design Results to
the design criteria in DOE O 420.1C. If the contractor used design criteria other than those
documented in DOE O 420.1C, this section documents the evaluation of the alternate criteria and
assess the acceptability of those criteria.
8.7.12 Conditions of Approval for Proceeding to the Next Stage of Design
This section documents any conditions of approval for proceeding to the next stage of design.
The section also documents any recommendation that the project is not ready to proceed to the
next phase of design. This section may also indicate whether SBAA (or the SBRT) has any
fundamental problems with the developing design. Such problems should be elevated to the
attention of upper-level DOE managers in a timely manner. The early identification and
communication of fundamental problems is one of the key reasons for this incremental review of
the design. Resolution of these issues at an early stage will reduce the cost to correct these
problems at a later date, so it is important for the reviewer to make such issues known.
8.7.13 Conclusion
This section summarizes the significant issues in the review and document whether the CSDR or
the Preliminary Safety and Design Results is acceptable.
DOE-STD-1104-2016
53
9.0 REFERENCES AND ACRONYMS
9.1 REFERENCES
a. Code of Federal Regulations
(1) 10 CFR Part 830, Nuclear Safety Management
b. DOE Directives
(1) DOE O 231.1B, Chg. 1, Environment, Safety and Health Reporting
(2) DOE O 413.3B, Chg. 2, Program and Project Management for the Acquisition of Capital
Assets
(3) DOE O 420.1C, Chg. 1, Facility Safety
(4) DOE O 426.1, Chg. 1, Federal Technical Capability
(5) DOE O 442.2, Chg. 1, Differing Professional Opinions for Technical Issues Involving
Environment, Safety and Health
(6) DOE O 450.2, Integrated Safety Management
(7) DOE O 460.1C, Packaging and Transportation Safety
Section 47
c. DOE Guides
(1) DOE G 226.1-2A, Federal Line Management Oversight of Department of Energy
Nuclear Facilities
(2) DOE G 413.3-4A, Technology Readiness Assessment Guide
(3) DOE G 420.1-1A, Nonreactor Nuclear Safety Design Guide for use with DOE O 420.1C,
Facility Safety
(4) DOE G 423.1-1B, Implementation Guide for Use in Developing Technical Safety
Requirements
(5) DOE G 424.1-1B, Implementation Guide for Use in Addressing Unreviewed Safety
Question Requirements
d. DOE Technical Standards
(1) DOE-STD-1027-92, Chg. 1, Hazard Categorization and Accident Analysis Techniques
for Compliance with DOE Order 5480.23, Nuclear Safety Analysis Reports, September
1997
(2) DOE-STD-1083-2009 (Reaffirmed 2015), Processing Exemptions to Nuclear Safety
Rules and Approval of Alternative Methods for Documented Safety Analyses
(3) DOE-STD-1120-2016, Preparation of Documented Safety Analysis for Decommissioning
and Environmental Restoration Activities
(4) DOE-STD-1183-2016, Nuclear Safety Specialist Functional Area Qualification Standard
(5) DOE-STD-1186-2016, Specific Administrative Controls (forthcoming)
(6) DOE-STD-1189-2008, Integration of Safety into the Design Process
(7) DOE-STD-1189-2016, Integration of Safety into the Design Process
http://www.ecfr.gov/cgi-bin/text-idx?SID=a0c002576300290ee9266a424fd0d7ee&mc=true&node=pt10.4.830&rgn=div5
https://www.directives.doe.gov/directives-documents/200-series/0231.1-BOrder-b-admchg1
https://www.directives.doe.gov/directives-documents/400-series/0413.3-BOrder-b-chg2-pgchg
https://www.directives.doe.gov/directives-documents/400-series/0420.1-BOrder-C-chg1
https://www.directives.doe.gov/directives-documents/400-series/0426.1-BOrder-chg1
https://www.directives.doe.gov/directives-documents/400-series/0442.2-BOrder-chg1-pgchg
https://www.directives.doe.gov/directives-documents/400-series/0450.2-BOrder
https://www.directives.doe.gov/directives-documents/400-series/0460.1-BOrder-c
https://www.directives.doe.gov/directives-documents/200-series/0226.1-EGuide-2a
https://www.directives.doe.gov/directives-documents/400-series/0413.3-EGuide-04-admchg1
https://www.directives.doe.gov/directives-documents/400-series/0420.1-EGuide-1a
https://www.directives.doe.gov/directives-documents/400-series/0423.1-EGuide-1b
https://www.directives.doe.gov/directives-documents/400-series/0424.1-EGuide-1b-admchg2
http://energy.gov/ehss/downloads/doe-std-1027-92
http://energy.gov/ehss/downloads/doe-std-1083-2009-0
http://energy.gov/ehss/downloads/doe-std-1120-2016
http://energy.gov/ehss/downloads/doe-std-1183-2016
http://energy.gov/ehss/downloads/doe-std-1189-2008
DOE-STD-1104-2016
54
(8) DOE-STD-1628-2013, Development of Probabilistic Risk Assessments for Nuclear Safety
Applications
(9) DOE-STD-3009-94, Change Notice 1, January 2000, Preparation Guide for U.S.
Department of Energy Nonreactor Nuclear Facility Safety Analysis Reports
(10) DOE-STD-3009-2014, Preparation of Nonreactor Nuclear Facility Documented Safety
Analysis
(11) DOE-STD-3011-2016, Preparation of Documented Safety Analysis for Interim
Operations at DOE Nuclear Facilities
(12) DOE-NA-STD-3016-2006, Hazard Analysis Reports for Nuclear Explosive Operations
e. DOE Handbooks
(1) DOE-HDBK-3010-94, Airborne Release Fractions/Rates and Respirable Fractions for
Nonreactor Nuclear Facilities
9.2 ACRONYMS
Section 48
CD Critical Decision
CFR Code of Federal Regulations
CSDR Conceptual Safety Design Report
CTA Central Technical Authority
DBA Design Basis Accident
DOE Department of Energy
DSA Documented Safety Analysis
EBA Evaluation Basis Accident
EG Evaluation Guideline
ESS Evaluation of the Safety of the Situation
G Guide
JCO Justification for Continued Operation
LCO Limiting Conditions of Operation
NNSA National Nuclear Security Administration
NPH Natural Phenomena Hazard
O Order
PDSA Preliminary Documented Safety Analysis
PISA Potentially Inadequate Safety Analysis
PSO Program Secretarial Office/r
SAC Specific Administrative Control
SBAA Safety Basis Approval Authority
SBRT Safety Basis Review Team
SDIT Safety Design Integration Team
SDS Safety Design Strategy
SER Safety Evaluation Report
SSC Structures, Systems, and Component
STD Standard
TSR Technical Safety Requirement
USQ Unreviewed Safety Question
USQD Unreviewed Safety Question Determination
http://energy.gov/ehss/downloads/doe-std-1628-2013
http://energy.gov/ehss/downloads/doe-std-3009-94
http://energy.gov/ehss/downloads/doe-std-3009-2014
http://energy.gov/ehss/downloads/doe-std-3011-2016
http://energy.gov/ehss/downloads/doe-na-std-3016-2016
http://energy.gov/ehss/downloads/doe-hdbk-3010-94
FOREWORD
1.0 INTRODUCTION
2.0 APPLICABILITY AND SCOPE
3.0 MANAGEMENT AND COORDINATION OF SAFETY BASES REVIEWS
3.1 Responsibilities and Authorities
3.2 Delegations of Authority
3.3 Planning
3.4 Interactions
3.5 Issue Origination and Resolution
4.0 APPROVAL OF DOCUMENTED SAFETY ANALYSES
4.1 Bases for Approval
4.2 Base Information
4.3 Hazard and Accident Analyses
4.4 Defense-in-Depth
4.5 Safety Structures, Systems, and Components (SSCs)
4.6 Specific Administrative Controls
4.7 Derivation of Technical Safety Requirements
4.8 Safety Management Programs
4.9 Existing Facilities with Mitigated Offsite Consequence Estimates over the EG
4.10 Conditions of Approval
4.11 Rejection of a DSA
5.0 APPROVAL OF TECHNICAL SAFETY REQUIREMENTS
5.1 Management and Coordination
5.2 Bases of Approval
5.3 TSR Consistency with the DSA
5.4 TSR Consistency with DOE G 423.1-1B
6.0 APPROVAL OF OTHER SAFETY BASIS RELATED DOCUMENTS
6.1 Unreviewed Safety Question Process Procedure
6.2 Documents that Result from Positive USQ Determinations
6.2.1 Evaluation of the Safety of the Situation
6.2.2 Justification for Continued Operation
6.3 Downgrades in Facility Hazard Categorization to “Below Hazard Category 3” Status
7.0 SAFETY EVALUATION REPORTS
7.1 General Discussion
7.1.1 Review of PDSAs
7.1.2 Review of Safety Basis Changes and DSA Annual Updates
7.2 SER Content and Format
7.2.1 Title Page
7.2.2 Signature Page
7.2.3 Executive Summary
7.2.4 Review Process
7.2.5 Base Information
7.2.6 Hazard and Accident Analyses
7.2.7 Safety Structures, Systems, and Components (SSCs)
7.2.8 Specific Administrative Controls
7.2.9 Derivation of Technical Safety Requirements
7.2.10 Safety Management Programs
7.2.11 Technical Safety Requirements
7.2.12 Conditions of Approval
7.2.13 Records
7.3 Safety Basis Information System Database
Section 49
8.0 SAFETY DESIGN BASIS DOCUMENTS
8.1 Safety Basis Review Team
8.2 Review Bases for Safety Design Strategy
8.3 Review Bases for Conceptual Safety Design Reports
8.4 Review of Long-lead Procurement SSCs
8.5 Review Bases for Preliminary Safety and Design Results
8.6 Approval Bases for Preliminary Documented Safety Analyses
8.7 Safety Review Letters
8.7.1 Executive Summary
8.7.2 Review Process
8.7.3 Recommendation to Proceed
8.7.4 Site and Facility Information
8.7.5 Hazard Analysis
8.7.6 Hazard Categorization
8.7.7 Safety Structures, Systems, and Components
8.7.8 Specific Administrative Controls
8.7.9 Other Hazard Controls
8.7.10 Design Codes and Standards
8.7.11 Safety Design Criteria
8.7.12 Conditions of Approval for Proceeding to the Next Stage of Design
8.7.13 Conclusion
9.0 REFERENCES AND ACRONYMS
9.1 References
9.2 Acronyms